◆ CRITICAL 01 — Ubiquiti UniFi OS Triple Flaw — CVSS 10.0, Root RCE Chain (CVE-2026-34908/34909/34910)
On June 23, CISA added three Ubiquiti UniFi OS vulnerabilities to the KEV catalog after confirming active exploitation. The improper access control, path traversal, and command injection flaws each score CVSS 10.0 and chain to unauthenticated remote code execution with full root privileges. Reported activity includes a Mirai/Gafgyt botnet campaign against internet-facing UniFi Network Application hosts.
Federal patch deadline was June 26. Network-edge appliances managing VLAN segmentation and identity boundaries map to NIST 800-171 3.13.1/3.13.5 (boundary protection) and 3.14.1 (flaw remediation). Compromised controllers warrant post-exploitation investigation, not just patching, given confirmed botnet enrollment.
