UniFi Security Advisory Bulletin 069: Six Unauthenticated DoS Bugs in UniFi Gateways, and How I Work the Patch

On September 22, 2026, Ubiquiti published Security Advisory Bulletin 069. It covers six vulnerabilities in UniFi gateway products: three out-of-bounds writes, two out-of-bounds reads, and one uncontrolled recursion bug. Each one is rated CVSS 7.5 (High). The Canadian Centre for Cyber Security followed with its own advisory (AV26-954) the next day.
Compared to what Ubiquiti disclosed a month ago, this one isn’t a five-alarm fire. But it lands on the device that matters most at a small site, the gateway, so I want to walk through what it is, what it isn’t, and how I’d actually get it patched.
What Bulletin 069 actually says
The six CVEs are:
- CVE-2026-77544
- CVE-2026-77555
- CVE-2026-77556
- CVE-2026-77558
- CVE-2026-95861
- CVE-2026-95862
The published CVSS vector for CVE-2026-77544 is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. In plain English: reachable over the network, low complexity, no login needed, no user interaction, and the impact is availability only. Someone who can reach the vulnerable service can knock the gateway over. They can’t read your data or take over the box with these bugs.
As of the reporting I’ve seen, there is no known active exploitation.
Affected products and fixed versions
| Product | Fixed version |
|---|---|
| Dream Machines | UniFi OS 5.1.31 or later |
| Enterprise Firewalls | UniFi OS 5.1.31 or later |
| Dream Routers | UniFi OS 5.1.31 or later |
| Cloud Gateways | UniFi OS 5.1.31 or later |
| Dream Wall | UniFi OS 5.1.31 or later |
| Express 7 | 5.1.31 or later |
| UniFi Gateways | 5.1.26 or later |
| Express | 4.0.21 or later |
📝 Note: If you already moved your consoles to UniFi OS 5.1.31 for Bulletin 067 back in August, the fixed version for the Dream-family devices is the same build. Check your versions anyway, but you may already be covered.
Why “only” a DoS still matters at a small site
At an enterprise, a gateway DoS is an incident. At a ten-person office on the North Coast, the gateway is often the whole network: routing, firewall, VPN, DHCP, and on a lot of UniFi installs, the console that runs Protect and Access too. If it falls over, the office is offline, the remote camera view is gone, and anything that depends on the cloud for door management is waiting on a reboot.
For the clients we support at Emerald Security, most of the value of a UniFi stack is that it’s one system. That’s also why an availability bug on the gateway reaches further than the CVSS number suggests.
The other reason to take it seriously is context. On August 26, 2026, Ubiquiti published Security Advisory Bulletin 067, which disclosed 22 vulnerabilities, 21 of them rated 9.0 or higher, including three at CVSS 10.0: an authentication bypass in UniFi OS (CVE-2026-77550), and command injection in UniFi Protect (CVE-2026-77537) and UniFi Talk (CVE-2026-77554). Censys reported seeing 102,607 hosts exposing a UniFi OS management interface to the internet at the time. If a site never got the August updates, Bulletin 069 is a good excuse to finally close both.
How I’d work the patch
This is the order I’d follow for a small fleet of client sites. None of it is fancy. The point is to not find out about a bad update from an angry phone call.
- Inventory first. Pull every gateway and console with its model and current firmware. UniFi Site Manager shows this per host. Put it in a spreadsheet or CSV, because you’ll use it again next month.
- Take a fresh backup. Download a console backup before touching anything. If you already have scheduled backups running, confirm the most recent one actually exists and is recent. I run scheduled backups on my own UniFi NAS, and I still check before a firmware change.
- Pick the window. A gateway update reboots the gateway. On a console that also runs Protect, recording pauses during the reboot. Schedule it after hours and tell the client.
- Update the gateway, then verify. Confirm the version after the reboot, confirm WAN is up, confirm VPN and any site-to-site tunnels came back, and confirm cameras are recording again.
- Check exposure while you’re in there. If the management interface is reachable from the internet, fix that too. Remote management through UniFi’s cloud access doesn’t require opening the console’s web UI or SSH to the WAN.
- Record it. Date, old version, new version, who did it. Next time there’s a bulletin, the inventory is already done.
Checking your inventory against the fixed versions
Once you have that CSV, a short Python script will tell you which devices are still below the fixed version. This uses only the standard library.
Example unifi_inventory.csv:
site,device,product_line,version
Main Office,Gateway,cloud-gateway,5.1.26
Warehouse,Gateway,unifi-gateway,5.1.26
Branch,Router,express,4.0.20
Home Office,UDR,dream-router,5.1.31
And the checker:
#!/usr/bin/env python3
"""Flag UniFi gateways below the fixed versions in Security Advisory Bulletin 069."""
import csv
import sys
# Minimum fixed versions from Bulletin 069 (published 2026-09-22)
FIXED = {
"dream-machine": "5.1.31",
"enterprise-firewall": "5.1.31",
"dream-router": "5.1.31",
"cloud-gateway": "5.1.31",
"dream-wall": "5.1.31",
"express-7": "5.1.31",
"unifi-gateway": "5.1.26",
"express": "4.0.21",
}
def vtuple(version: str) -> tuple:
"""Turn '5.1.31' into (5, 1, 31) so versions compare numerically."""
return tuple(int(part) for part in version.strip().split("."))
def main(path: str) -> int:
needs_update = 0
with open(path, newline="") as fh:
for row in csv.DictReader(fh):
line = row["product_line"].strip().lower()
fixed = FIXED.get(line)
if fixed is None:
print(f"SKIP {row['site']:<15} {row['device']:<12} unknown product line '{line}'")
continue
if vtuple(row["version"]) < vtuple(fixed):
needs_update += 1
print(f"UPDATE {row['site']:<15} {row['device']:<12} {row['version']} -> {fixed}+")
else:
print(f"OK {row['site']:<15} {row['device']:<12} {row['version']}")
print(f"\n{needs_update} device(s) below the Bulletin 069 fixed version.")
return 1 if needs_update else 0
if __name__ == "__main__":
sys.exit(main(sys.argv[1] if len(sys.argv) > 1 else "unifi_inventory.csv"))
It exits non-zero when something needs updating, so you can drop it into a scheduled job or a monitoring check later.
Checking what the internet can see
Bulletin 069 only needs network access, and Bulletin 067 included an unauthenticated management-plane bug, so it’s worth confirming what’s reachable from outside. Run this from a machine outside the client network (a cloud VM works well). Only scan addresses you’re responsible for.
#!/usr/bin/env bash
# Check whether HTTPS or SSH answers on each WAN IP listed in wan_ips.txt
# Usage: ./wan_check.sh wan_ips.txt
set -euo pipefail
file="${1:-wan_ips.txt}"
while read -r ip; do
[[ -z "$ip" || "$ip" == \#* ]] && continue
code=$(curl -sk --max-time 5 -o /dev/null -w '%{http_code}' "https://${ip}/" || true)
if [[ "$code" != "000" ]]; then
echo "${ip}: HTTPS answered (HTTP ${code}) - confirm this is intentional"
else
echo "${ip}: HTTPS closed or filtered"
fi
if timeout 5 bash -c "exec 3<>/dev/tcp/${ip}/22" 2>/dev/null; then
echo "${ip}: SSH port 22 open - restrict or disable"
else
echo "${ip}: SSH closed or filtered"
fi
done < "$file"
If either one answers and you didn’t intend it, that’s the bigger problem to fix this week.
What I tell clients
For a non-technical client, the short version is: “There’s a fix for your internet gateway that prevents someone from knocking your office offline. It takes a reboot of a few minutes, and we’ll do it after hours.” That’s honest, and it doesn’t turn a High-severity DoS into a scare story.
For other MSPs, my take is that Bulletin 069 is a process check more than an emergency. If your UniFi fleet is already on 5.1.31 from August, you spend ten minutes confirming it. If it isn’t, you now have two bulletins’ worth of reasons, and one of them was rated 10.0.
Sources
- Ubiquiti Security Advisory (AV26-954) — Canadian Centre for Cyber Security, September 23, 2026
- Security Advisory Bulletin 069 — Ubiquiti Community, September 22, 2026
- CVE-2026-77544: Dream Machines Out-of-Bounds Write (CVSS 7.5) — Strix, published September 22, 2026
- High-Severity DoS Flaws Patched in Ubiquiti UniFi Firewalls and Gateways — Mallory, September 23, 2026
- August 28 Advisory: Ubiquiti Security Advisory Bulletin Discloses 21 Critical Vulnerabilities — Censys, August 28, 2026
- Ubiquiti Releases Security Advisory Bulletin for Multiple Critical Vulnerabilities in UniFi Products — NHS England Digital, August 27, 2026

