FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
Ubiquiti UniFi CVE-2026-22557 (CVSS 10): Three Max-Severity Flaws in One Year — Your Management Plane Is the Attack Surface
NewsDevOps

Ubiquiti UniFi CVE-2026-22557 (CVSS 10): Three Max-Severity Flaws in One Year — Your Management Plane Is the Attack Surface

via Dev.to DevOpsFirstPassLab2h ago

CVE-2026-22557 dropped on March 18, 2026 — a CVSS 10.0 path traversal in Ubiquiti's UniFi Network Application that lets an unauthenticated attacker with network access take over any account, including admin. No credentials needed. No user interaction required. That's bad enough on its own. But here's the real story: this is the third maximum-severity vulnerability in UniFi Network Application within 12 months. That's not bad luck — that's an architectural pattern. If you run UniFi (and statistically, a lot of you do — it's the go-to for home labs, SMBs, and budget-conscious campus deployments), patch immediately and read on. What's the Vulnerability? Attribute Detail CVE CVE-2026-22557 CVSS Score 10.0 (Maximum) Type Path traversal Attack Vector Network (unauthenticated) Impact Full account takeover including admin Affected UniFi Network Application ≤ 9.0.118, ≤ 10.1.89, ≤ 10.2.97 Patched March 18, 2026 Exploited in wild? Not yet (as of March 21) The attack: send crafted requests to the

Continue reading on Dev.to DevOps

Opens in a new tab

Read Full Article
5 views

Related Articles

News

ACME device attestation, smallstep and pkcs11: attezt

Lobsters • 3h ago

Why You Keep Pushing Doors That Say ‘Pull’ — And Why It Matters for Your Code
News

Why You Keep Pushing Doors That Say ‘Pull’ — And Why It Matters for Your Code

Medium Programming • 3h ago

bye bye RTMP
News

bye bye RTMP

Lobsters • 4h ago

I have a question, I am developing an app. I am having the issue in which my app is logging out my acc, after some time like in 20 Min. Anyone know what the issue could be and how can I fix it. a question from newbee
News

I have a question, I am developing an app. I am having the issue in which my app is logging out my acc, after some time like in 20 Min. Anyone know what the issue could be and how can I fix it. a question from newbee

Dev.to • 4h ago

I got tired of BLoC boilerplate. So I built my own state manager.
News

I got tired of BLoC boilerplate. So I built my own state manager.

Medium Programming • 5h ago

Discover More Articles