Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1301 articles · 106378 vulns · 36/55 feeds (7d)
← Back to list
8.8
CVE-2026-22559

An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected

Description

An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected Products: UniFi Network Server (Version 10.1.85 and earlier) Mitigation: Update UniFi Network Server to Version 10.1.89 or later.

Affected Products

VendorProductVersions
UbiquitiUniFi Network Server10.1.88, 10.2.93, 9.0.114

References

  • https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b

Related News (3 articles)

Tier B
BSI Advisories1h ago
[NEU] [hoch] Ubiquiti UniFi Network Server: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB16h ago
CVE-2026-22559 | Ubiquiti UniFi Network Server up to 10.1.88 Link input validation (EUVD-2026-14988)
→ No new info (linked only)
Tier B
CCCS Canada5d ago
Ubiquiti security advisory (AV26-258)
→ No new info (linked only)
CVSS 3.18.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-20
Published3/24/2026
Last enriched2h agov3
Trending Score55
Source articles5
Independent3
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 2h ago
v3Tier B2h ago

Updated severity to CRITICAL, added new affected versions 10.2.93 and 9.0.114, and marked the vulnerability as actively exploited with an exploit available.

affectedVersionsseverityexploitAvailableactivelyExploited
via CCCS Canada
v2Tier C2h ago

Updated vendor to Ubiquiti, product to UniFi Network Server, affected versions to include 10.1.88, changed severity to CRITICAL, and noted that the vulnerability is actively exploited.

vendorproductaffectedVersionspatchAvailable
via VulDB
v110h ago

Initial creation