CVE Tools

Udm

18 CVEs tracked. 3 of them are in CISA KEV.

This hub aggregates every CVE we track for Udm, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Udm CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Udm CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-024
2026-034
2026-040
2026-054
2026-064
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical528%
  • High950%
  • Medium422%

Latest CVEs

The 15 most recently published vulnerabilities affecting Udm.

  1. CVE-2026-48610Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized ...8.1
  2. CVE-2026-47368A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.8.6
  3. CVE-2026-47370A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection wit...9.9
  4. CVE-2026-47369A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such...9.9
  5. CVE-2026-34911A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipul...7.7
  6. CVE-2026-34909A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an u...10.0
  7. CVE-2026-34908A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.10.0
  8. CVE-2026-34910A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.10.0
  9. CVE-2026-33192free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques5.3
  10. CVE-2026-33065free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request5.3
  11. CVE-2026-33064free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference7.5
  12. CVE-2026-33191free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error8.6
  13. CVE-2026-27642free5GC has Improper Input Validation in UDM UEAU Service7.5
  14. CVE-2025-69252free5GC has Null Pointer Dereference in UDM, Leading to Service Panic7.5
  15. CVE-2025-69251free5GC has Improper Input Validation in UDM, Leading to Information Exposure5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store