CVE Tools

Unifi Network Application

16 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Unifi Network Application, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Unifi Network Application CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Unifi Network Application CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-032
2026-040
2026-050
2026-060
2026-075
2026-082
2026-090

Severity

How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical531%
  • High850%
  • Medium319%

Latest CVEs

The 15 most recently published vulnerabilities affecting Unifi Network Application.

  1. CVE-2026-77541A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Ne...9.1
  2. CVE-2026-77535A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an ado...9.1
  3. CVE-2026-56842A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniF...7.5
  4. CVE-2026-55114A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Net...8.8
  5. CVE-2026-55118A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privil...8.3
  6. CVE-2026-54406A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permissio...8.7
  7. CVE-2026-54405A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.7.5
  8. CVE-2026-22557A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated t...10.0
  9. CVE-2026-22558An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.7.7
  10. CVE-2025-24292A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MA...6.8
  11. CVE-2024-42028A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) allows a malicious actor with a local operational ...8.8
  12. CVE-2024-42025A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell acc...7.8
  13. CVE-2024-27981A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Applic...9.8
  14. CVE-2023-41721Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creatin...5.3
  15. CVE-2023-32000A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an A...4.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store