AdvisoryBleeping Computer
10.0 — CRITICAL
CISA warns of max severity Ubiquiti flaws exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Hackers are actively exploiting multiple vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers, posing a significant threat to federal agencies and organizations managing these systems.
⚙️Technical Details
CVEs
CVE-2026-34908CVE-2026-34909CVE-2025-67038
Affected Systems
Ubiquiti UniFi OS devicesLantronix EDS5000 serial-to-ethernet servers
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Federal agencies and organizations managing Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers
🛡️Recommended Actions
1Apply available security updates or vendor-recommended mitigations for the affected systems as soon as possible.
2Conduct a thorough vulnerability scan to identify and remediate any potential weaknesses in the network.
3Monitor system logs and network traffic for signs of suspicious activity related to these vulnerabilities.
📦Affected Products
Ui Enterprise Fortress GatewayUi Enterprise Fortress Gateway FirmwareUi Enterprise Network Video RecorderUi Enterprise Network Video Recorder CoreUi Enterprise Network Video Recorder Core FirmwareUi Enterprise Network Video Recorder FirmwareUi Unas 2Ui Unas 2 FirmwareUi Unas 4Ui Unas 4 Firmware
🔐NVD Verified DataVERIFIED
CVE-2026-34908 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-284
Affected Products (CPE)
Ui Enterprise Fortress GatewayUi Enterprise Fortress Gateway FirmwareUi Enterprise Network Video RecorderUi Enterprise Network Video Recorder CoreUi Enterprise Network Video Recorder Core Firmware
CVE-2026-34909 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-22
Affected Products (CPE)
Ui Enterprise Fortress GatewayUi Enterprise Fortress Gateway FirmwareUi Enterprise Network Video RecorderUi Enterprise Network Video Recorder CoreUi Enterprise Network Video Recorder Core Firmware
CVE-2025-67038 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-94
Affected Products (CPE)
Lantronix Eds5008Lantronix Eds5008 FirmwareLantronix Eds5016Lantronix Eds5016 FirmwareLantronix Eds5032
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
