Now Hiring: Do not apply for this junior installation engineer’s job. It’s highly unlikely you’d enjoy it

UniFi Security Advisory Bulletin 069: Six Unauthenticated DoS Bugs in UniFi Gateways, and How I Work the Patch

UniFi Security Advisory Bulletin 069: Six Unauthenticated DoS Bugs in UniFi Gateways, and How I Work the Patch

UniFi patch workflow: inventory, backup, schedule, update, verify, check WAN exposure, record
Critical Vulnerabilities / Cybersecurity / Enterprise Networks / UniFi Ecosystem

On September 22, 2026, Ubiquiti published Security Advisory Bulletin 069. It covers six vulnerabilities in UniFi gateway products: three out-of-bounds writes, two out-of-bounds reads, and one uncontrolled recursion bug. Each one is rated CVSS 7.5 (High). The Canadian Centre for Cyber Security followed with its own advisory (AV26-954) the next day.

Compared to what Ubiquiti disclosed a month ago, this one isn’t a five-alarm fire. But it lands on the device that matters most at a small site, the gateway, so I want to walk through what it is, what it isn’t, and how I’d actually get it patched.

What Bulletin 069 actually says

The six CVEs are:

  • CVE-2026-77544
  • CVE-2026-77555
  • CVE-2026-77556
  • CVE-2026-77558
  • CVE-2026-95861
  • CVE-2026-95862

The published CVSS vector for CVE-2026-77544 is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. In plain English: reachable over the network, low complexity, no login needed, no user interaction, and the impact is availability only. Someone who can reach the vulnerable service can knock the gateway over. They can’t read your data or take over the box with these bugs.

As of the reporting I’ve seen, there is no known active exploitation.

Affected products and fixed versions

ProductFixed version
Dream MachinesUniFi OS 5.1.31 or later
Enterprise FirewallsUniFi OS 5.1.31 or later
Dream RoutersUniFi OS 5.1.31 or later
Cloud GatewaysUniFi OS 5.1.31 or later
Dream WallUniFi OS 5.1.31 or later
Express 75.1.31 or later
UniFi Gateways5.1.26 or later
Express4.0.21 or later

📝 Note: If you already moved your consoles to UniFi OS 5.1.31 for Bulletin 067 back in August, the fixed version for the Dream-family devices is the same build. Check your versions anyway, but you may already be covered.

Why “only” a DoS still matters at a small site

At an enterprise, a gateway DoS is an incident. At a ten-person office on the North Coast, the gateway is often the whole network: routing, firewall, VPN, DHCP, and on a lot of UniFi installs, the console that runs Protect and Access too. If it falls over, the office is offline, the remote camera view is gone, and anything that depends on the cloud for door management is waiting on a reboot.

For the clients we support at Emerald Security, most of the value of a UniFi stack is that it’s one system. That’s also why an availability bug on the gateway reaches further than the CVSS number suggests.

The other reason to take it seriously is context. On August 26, 2026, Ubiquiti published Security Advisory Bulletin 067, which disclosed 22 vulnerabilities, 21 of them rated 9.0 or higher, including three at CVSS 10.0: an authentication bypass in UniFi OS (CVE-2026-77550), and command injection in UniFi Protect (CVE-2026-77537) and UniFi Talk (CVE-2026-77554). Censys reported seeing 102,607 hosts exposing a UniFi OS management interface to the internet at the time. If a site never got the August updates, Bulletin 069 is a good excuse to finally close both.

How I’d work the patch

This is the order I’d follow for a small fleet of client sites. None of it is fancy. The point is to not find out about a bad update from an angry phone call.

  1. Inventory first. Pull every gateway and console with its model and current firmware. UniFi Site Manager shows this per host. Put it in a spreadsheet or CSV, because you’ll use it again next month.
  2. Take a fresh backup. Download a console backup before touching anything. If you already have scheduled backups running, confirm the most recent one actually exists and is recent. I run scheduled backups on my own UniFi NAS, and I still check before a firmware change.
  3. Pick the window. A gateway update reboots the gateway. On a console that also runs Protect, recording pauses during the reboot. Schedule it after hours and tell the client.
  4. Update the gateway, then verify. Confirm the version after the reboot, confirm WAN is up, confirm VPN and any site-to-site tunnels came back, and confirm cameras are recording again.
  5. Check exposure while you’re in there. If the management interface is reachable from the internet, fix that too. Remote management through UniFi’s cloud access doesn’t require opening the console’s web UI or SSH to the WAN.
  6. Record it. Date, old version, new version, who did it. Next time there’s a bulletin, the inventory is already done.

Checking your inventory against the fixed versions

Once you have that CSV, a short Python script will tell you which devices are still below the fixed version. This uses only the standard library.

Example unifi_inventory.csv:

site,device,product_line,version
Main Office,Gateway,cloud-gateway,5.1.26
Warehouse,Gateway,unifi-gateway,5.1.26
Branch,Router,express,4.0.20
Home Office,UDR,dream-router,5.1.31

And the checker:

#!/usr/bin/env python3
"""Flag UniFi gateways below the fixed versions in Security Advisory Bulletin 069."""
import csv
import sys

# Minimum fixed versions from Bulletin 069 (published 2026-09-22)
FIXED = {
    "dream-machine": "5.1.31",
    "enterprise-firewall": "5.1.31",
    "dream-router": "5.1.31",
    "cloud-gateway": "5.1.31",
    "dream-wall": "5.1.31",
    "express-7": "5.1.31",
    "unifi-gateway": "5.1.26",
    "express": "4.0.21",
}


def vtuple(version: str) -> tuple:
    """Turn '5.1.31' into (5, 1, 31) so versions compare numerically."""
    return tuple(int(part) for part in version.strip().split("."))


def main(path: str) -> int:
    needs_update = 0
    with open(path, newline="") as fh:
        for row in csv.DictReader(fh):
            line = row["product_line"].strip().lower()
            fixed = FIXED.get(line)
            if fixed is None:
                print(f"SKIP   {row['site']:<15} {row['device']:<12} unknown product line '{line}'")
                continue
            if vtuple(row["version"]) < vtuple(fixed):
                needs_update += 1
                print(f"UPDATE {row['site']:<15} {row['device']:<12} {row['version']} -> {fixed}+")
            else:
                print(f"OK     {row['site']:<15} {row['device']:<12} {row['version']}")
    print(f"\n{needs_update} device(s) below the Bulletin 069 fixed version.")
    return 1 if needs_update else 0


if __name__ == "__main__":
    sys.exit(main(sys.argv[1] if len(sys.argv) > 1 else "unifi_inventory.csv"))

It exits non-zero when something needs updating, so you can drop it into a scheduled job or a monitoring check later.

Checking what the internet can see

Bulletin 069 only needs network access, and Bulletin 067 included an unauthenticated management-plane bug, so it’s worth confirming what’s reachable from outside. Run this from a machine outside the client network (a cloud VM works well). Only scan addresses you’re responsible for.

#!/usr/bin/env bash
# Check whether HTTPS or SSH answers on each WAN IP listed in wan_ips.txt
# Usage: ./wan_check.sh wan_ips.txt
set -euo pipefail

file="${1:-wan_ips.txt}"

while read -r ip; do
  [[ -z "$ip" || "$ip" == \#* ]] && continue

  code=$(curl -sk --max-time 5 -o /dev/null -w '%{http_code}' "https://${ip}/" || true)
  if [[ "$code" != "000" ]]; then
    echo "${ip}: HTTPS answered (HTTP ${code}) - confirm this is intentional"
  else
    echo "${ip}: HTTPS closed or filtered"
  fi

  if timeout 5 bash -c "exec 3<>/dev/tcp/${ip}/22" 2>/dev/null; then
    echo "${ip}: SSH port 22 open - restrict or disable"
  else
    echo "${ip}: SSH closed or filtered"
  fi
done < "$file"

If either one answers and you didn’t intend it, that’s the bigger problem to fix this week.

What I tell clients

For a non-technical client, the short version is: “There’s a fix for your internet gateway that prevents someone from knocking your office offline. It takes a reboot of a few minutes, and we’ll do it after hours.” That’s honest, and it doesn’t turn a High-severity DoS into a scare story.

For other MSPs, my take is that Bulletin 069 is a process check more than an emergency. If your UniFi fleet is already on 5.1.31 from August, you spend ten minutes confirming it. If it isn’t, you now have two bulletins’ worth of reasons, and one of them was rated 10.0.

Sources

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare