Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Agentic AI Has an Identity Problem and Attackers Know It

    June 29, 2026

    Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026

    June 29, 2026

    Tidal Says It Won’t Pay Royalties for AI-Generated Music

    June 29, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»CISA warns of max severity Ubiquiti flaws exploited in attacks
    News

    CISA warns of max severity Ubiquiti flaws exploited in attacks

    adminBy adminJune 24, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    CISA warns of max severity Ubiquiti flaws exploited in attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers.

    According to the BOD 26-04 directive, federal agencies have three days to apply available security updates or vendor-recommended mitigations.

     

    image

    The Ubiquiti flaws that CISA added to its catalog of Known Exploited Vulnerabilities are:

    • CVE-2026-34908: an access control bypass flaw that allows an unauthenticated attacker to make unauthorized changes to a UniFi OS system, potentially leading to full system compromise.
    • CVE-2026-34909: a directory/path traversal vulnerability that allows an attacker to access sensitive files on the underlying operating system, potentially exposing configuration files, credentials, and other sensitive data that could facilitate account takeover.
    • CVE-2026-34910: an improper input validation flaw that enables an attacker to inject and execute arbitrary operating system commands, potentially leading to remote code execution and complete system takeover.

    Ubiquiti released security updates for the three vulnerabilities in May, warning that they could be exploited remotely without privileges.

    Researchers at Bishop Fox later demonstrated that the three flaws could be chained to achieve full remote code execution with elevated privileges on vulnerable UniFi OS devices.

    Bishop Fox has also released a free detection script on GitHub to help defenders discover vulnerable instances in their environment.

    The security issue exploited in Lantronix servers is tracked as CVE-2025-67038, and is a critical-severity root-level command injection affecting model EDS5000 running firmware 2.1.0.0R3.

    The vulnerability exists in the HTTP RPC module, which executes a shell command to log failed authentication attempts.

    The supplied username is concatenated directly into the shell command without proper sanitization, allowing an attacker to inject arbitrary operating system commands.

    Lantronix released a released a patch for CVE-2025-67038 and recommends users to upgrade to EDS5000 version 2.2.0.0R1.

    CISA has not shared any details about the observed exploitation of any of the four flaws, while the “use in ransomware campaigns” flag was set to “Unknown” for all of them.

    System administrators managing the above products are recommended to apply the available updates and/or suggested mitigations as soon as possible.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleInfosec News Nuggets — June 24, 2026 – AboutDFIR
    Next Article Vast ‘Structures’ In Space Reveal the Universe Isn’t What We Thought
    admin
    • Website

    Related Posts

    News

    Agentic AI Has an Identity Problem and Attackers Know It

    June 29, 2026
    News

    Tidal Says It Won’t Pay Royalties for AI-Generated Music

    June 29, 2026
    News

    Microsoft extends Windows Server 2022 hotpatching until October 2027

    June 29, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Our Picks

    Agentic AI Has an Identity Problem and Attackers Know It

    June 29, 2026

    Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026

    June 29, 2026

    Tidal Says It Won’t Pay Royalties for AI-Generated Music

    June 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.