Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1405 articles · 106454 vulns · 36/55 feeds (7d)
← Back to list
8.8
CVE-2026-22559

An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected

Description

An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected Products: UniFi Network Server (Version 10.1.85 and earlier) Mitigation: Update UniFi Network Server to Version 10.1.89 or later.

Affected Products

VendorProductVersions
UbiquitiUniFi Network Server10.1.88, 10.2.93, 9.0.114

References

  • https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b

Related News (3 articles)

Tier B
BSI Advisories3h ago
[NEU] [hoch] Ubiquiti UniFi Network Server: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB18h ago
CVE-2026-22559 | Ubiquiti UniFi Network Server up to 10.1.88 Link input validation (EUVD-2026-14988)
→ No new info (linked only)
Tier B
CCCS Canada5d ago
Ubiquiti security advisory (AV26-258)
→ No new info (linked only)
CVSS 3.18.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-20
Published3/24/2026
Last enriched4h agov3
Trending Score54
Source articles3
Independent3
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 4h ago
v3Tier B4h ago

Updated severity to CRITICAL, added new affected versions 10.2.93 and 9.0.114, and marked the vulnerability as actively exploited with an exploit available.

affectedVersionsseverityexploitAvailableactivelyExploited
via CCCS Canada
v2Tier C4h ago

Updated vendor to Ubiquiti, product to UniFi Network Server, affected versions to include 10.1.88, changed severity to CRITICAL, and noted that the vulnerability is actively exploited.

vendorproductaffectedVersionspatchAvailable
via VulDB
v112h ago

Initial creation