:

CISA WARNS OF CRITICAL UBIQUITI FLAWS UNDER ACTIVE ATTACK

SECURITY DESK1 MIN READ
WED, JUN 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about maximum severity vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers that are being actively exploited by hackers.

CISA added the flaws to its Known Exploited Vulnerabilities catalog, indicating real-world attack activity. The vulnerabilities affect Ubiquiti's UniFi OS platform, widely deployed in enterprise networks and critical infrastructure. Lantronix serial-to-ethernet servers, commonly used for remote device management, also contain exploitable flaws at the highest severity level. Organizations running affected versions should prioritize patching immediately. CISA recommends: - Applying available security updates without delay - Isolating affected systems if patches are unavailable - Monitoring network traffic for suspicious activity - Reviewing access logs for unauthorized connections No additional technical details about the specific vulnerabilities have been released publicly. Organizations should check Ubiquiti and Lantronix advisories for patch availability and affected product versions.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A threat actor compromised BdThemes' infrastructure and modified a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack leveraged the company's premium web-design plugin distribution system.

4H AGOAI Desk

HackerOne, the bug bounty platform, has come under criticism following recent policy shifts and operational decisions that have impacted its security researcher community.

5H AGOSecurity Desk

Simply deleting files from old USB drives before disposal provides minimal data protection. Experts warn that deleted data can be recovered with basic tools, making proper wiping essential.

8H AGOIndustry Desk

CISA has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices, including a critical server-side request forgery flaw.

10H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.