Security Advisory Bulletin 067 covers 22 UniFi vulnerabilities, including three command-injection issues in UniFi Protect. Integrators should identify affected Protect controllers and apply the relevant Protect and UniFi OS updates.

Key takeaways

  • UniFi Protect Application 7.1.87 and earlier is affected by three command-injection vulnerabilities covered in Bulletin 067.
  • Ubiquiti specifies UniFi Protect Application 7.2.105 or later as the remediation for the affected Protect issues.
  • One Protect issue, CVE-2026-77537, has a CVSS v3.1 score of 10.0 and is described as network-accessible without required privileges.
  • Bulletin 067 spans 22 vulnerabilities across UniFi products, so updating Protect alone may not address applicable console-level UniFi OS findings.
  • Installers and managed-service teams should verify the application and console OS versions actually installed, then test recording, live view, notifications, storage, and remote administration after maintenance.

Ubiquiti publishes Bulletin 067

Ubiquiti published Security Advisory Bulletin 067 on August 26, 2026, documenting 22 vulnerabilities across its UniFi software and device ecosystem. The bulletin includes issues in UniFi Protect, UniFi OS, UniFi Access, UniFi Talk, UniFi Connect, UniFi Network and related components. For video-security deployments, the immediate concern is a group of command-injection vulnerabilities in the UniFi Protect Application. ([community.ui.com](https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9?utm_source=openai))

paragraphs

Three critical Protect findings use the same fixed release

The advisory identifies CVE-2026-77536 and CVE-2026-77548 as improper-input-validation flaws in UniFi Protect that could allow command injection on the host device when an attacker has network access and low privileges. Both carry a CVSS v3.1 base score of 9.9. The bulletin also identifies CVE-2026-77537, another Protect command-injection issue, with a CVSS v3.1 score of 10.0; Ubiquiti describes that issue as exploitable by an actor with network access without privileges or user interaction. ([community.ui.com](https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9?utm_source=openai))

All three entries list UniFi Protect Application version 7.1.87 and earlier as affected. Ubiquiti’s specified remediation is to upgrade UniFi Protect to version 7.2.105 or later. The fixed-version target is significant because an installation may appear current at the console level while its individual application version remains behind the required release. ([community.ui.com](https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9?utm_source=openai))

Do not treat this as a Protect-only maintenance task

Although Protect is the central operational concern for camera and recorder deployments, Bulletin 067 is broader than a single application update. The advisory includes critical UniFi OS issues, including authentication-bypass findings affecting certain UniFi OS devices and instances. It also contains findings involving other applications such as Access, Connect and Talk. NHS England’s cyber advisory notes that 21 of the 22 listed vulnerabilities carry CVSS v3.1 scores of 9.0 or higher. ([digital.nhs.uk](https://digital.nhs.uk/cyber-alerts/2026/cc-4837))

For applicable appliance families, Ubiquiti’s associated UniFi OS 5.1.31 releases for Network Video Recorders and Cloud Gateways state that they fix issues referenced in Bulletin 067. UniFi OS Server has a separate remediation path in the bulletin, with version 5.1.37 or later specified for the affected server finding. Teams should consult the vendor bulletin against each installed product family rather than applying a single version number across all sites. ([community.ui.com](https://community.ui.com/releases/c922a942-a986-4151-9c39-45fa687be497?parentReplyIds=d353b610-70cb-40b9-9b72-d68ea71b3b65&replyId=3366792a-8c05-4e94-9964-f43f9cddc051&utm_source=openai))

What integrators should check first

Start with an inventory of Protect installations, including Network Video Recorders, console-hosted Protect deployments, and any managed sites that use local or remote administration. Record the installed UniFi Protect version, the UniFi OS version, device model, site owner, maintenance window and backup status. Prioritize systems where the management interface is reachable from less-trusted internal networks or where low-privilege operator accounts are widely assigned.

Next, apply the relevant Protect update to 7.2.105 or later and apply the UniFi OS remediation identified for the specific platform. Network segmentation and restricting management access remain prudent compensating measures, but they do not replace the vendor’s software updates. Avoid assuming that a camera firmware update alone addresses an application-level Protect vulnerability.

Validate security and operational behavior after the update

A security update on a video platform should be followed by an operational acceptance check. Confirm administrator and operator logins, live and recorded video access, camera adoption status, retention and storage health, motion or AI event delivery, notification workflows, and any remote-management or mobile-app access used by the customer. Where Protect is integrated with door access, identity, network or monitoring workflows, verify those handoffs as well.

For managed-service providers, preserve the pre-change version record and document the post-update versions in the site file. If a console cannot move directly to the required Protect release because of a platform dependency, treat that installation as an exception requiring a documented vendor-supported upgrade path and interim restriction of management-network exposure.

Procurement and lifecycle implication

The bulletin reinforces the value of including software-maintenance ownership in camera-system scope documents. A recorder, gateway or access-control deployment may contain a separate console OS and several UniFi applications, each with its own release cadence. Handover packages should identify who is responsible for tracking advisories, approving maintenance windows, maintaining backups and validating service after updates.

For new or refresh projects, teams should capture the exact controller model, operating-system branch and installed application versions at commissioning. That baseline can reduce the time needed to determine exposure when a vendor publishes a multi-product bulletin such as Bulletin 067.