Attackers can exploit three chained vulnerabilities in Ubiquiti's UniFi OS server to execute remote code with root privileges without authentication. The flaws have already been patched.
A critical security flaw in Ubiquiti's UniFi OS server allows unauthenticated attackers to gain root-level access by chaining three previously fixed vulnerabilities together.
The attack bypasses standard authentication mechanisms entirely, enabling remote code execution (RCE) with the highest system privileges. While Ubiquiti has released patches for each individual vulnerability, the combination creates a severe risk for systems running unpatched versions.
Vulnerability Chain
The three vulnerabilities work in conjunction to create an unauthenticated root access pathway. Attackers can leverage the flaws sequentially to escalate privileges and execute arbitrary commands on affected UniFi OS servers.
Ubiquiti has not disclosed extensive technical details about the specific vulnerabilities in public disclosures, but security researchers have documented the chaining technique. The attack requires network access to the UniFi OS server but does not require valid credentials.
Impact
UniFi OS powers Ubiquiti's network management platform, widely deployed across enterprise environments, data centers, and managed service providers. Successful exploitation grants attackers complete control over network infrastructure management systems, potentially exposing sensitive network configurations, user data, and connected devices.
Remediation
Ubiquiti recommends updating to the latest patched version of UniFi OS immediately. Users should verify their systems are running the current release, as all three vulnerabilities have been addressed in recent updates.
For organizations unable to patch immediately, restricting network access to UniFi OS servers through firewall rules and network segmentation can reduce exposure. Monitoring for suspicious authentication attempts and unauthorized access is also recommended.
Timeline
The vulnerabilities have been patched in recent Ubiquiti releases. Security researchers have confirmed the chaining technique works across multiple UniFi OS versions prior to the latest updates.
A threat actor deployed the open-source Hermes AI agent in unattended mode to automate post-exploitation activities during an alleged breach of Thailand's Ministry of Finance.
OnTrac, a major parcel delivery company, has notified customers of a network breach that may have exposed personal information. The hack compromised the company's corporate systems.
Slopsquatting, phantom domains, and HalluSquatting exploit identical vulnerabilities in AI coding agents. Security researchers warn that these attacks leverage late-binding patterns where AI systems trust non-existent packages and repositories.
Chick-fil-A confirmed a credential stuffing attack compromised over 13,000 customer accounts between June 17-19. The breach targeted the restaurant chain's website and mobile app.