boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Ubiquiti

Vendor reference — Ubiquiti · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow Ubiquiti — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs3736
KEV entries43
Rate & severity
KEV/100Med CVSSMed EPSSCHML
10.88.8.0036142110

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃█▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-120
2026-011
2026-020
2026-030
2026-040
2026-052
2026-068
2026-0725
2026-080

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-3491010.099.7CRITICALYES2026-06-23
CVE-2026-3490810.099.7CRITICALYES2026-06-23
CVE-2026-3490910.099.2CRITICALYES2026-06-23
CVE-2010-533098.3YES2022-04-15
CVE-2026-5074610.083.5CRITICAL2026-07-02
CVE-2026-544028.868.3HIGH2026-07-02
CVE-2026-330009.167.0CRITICAL2026-05-22
CVE-2026-507489.965.9CRITICAL2026-07-02
CVE-2026-473709.954.8CRITICAL2026-06-12
CVE-2026-473679.954.6CRITICAL2026-06-12
CVE-2026-349117.749.6HIGH2026-05-22
CVE-2026-544038.647.1HIGH2026-07-02
CVE-2026-551159.942.1CRITICAL2026-07-02
CVE-2026-544009.141.9CRITICAL2026-07-02
CVE-2026-507479.940.1CRITICAL2026-07-02

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-568427.512.0HIGH2026-07-02
CVE-2026-568418.820.5HIGH2026-07-02
CVE-2026-551198.113.0HIGH2026-07-02
CVE-2026-551188.310.7HIGH2026-07-02
CVE-2026-551178.631.5HIGH2026-07-02
CVE-2026-551169.834.7CRITICAL2026-07-02
CVE-2026-551159.942.1CRITICAL2026-07-02
CVE-2026-551148.817.9HIGH2026-07-02
CVE-2026-551137.513.2HIGH2026-07-02
CVE-2026-551128.810.0HIGH2026-07-02
CVE-2026-551117.526.6HIGH2026-07-02
CVE-2026-551106.14.5MEDIUM2026-07-02
CVE-2026-544098.119.7HIGH2026-07-02
CVE-2026-544089.823.1CRITICAL2026-07-02
CVE-2026-544078.623.8HIGH2026-07-02

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Express 7143
UniFi OS Server133
EFG83
UCG-Fiber83
UCG-Industrial83
UCG-Max83
UCG-Ultra83
UDM83
UDM-Beast83
UDM-Pro83
UDM-Pro-Max83
UDM-SE83
UDR83
UDR-5G83
UDR783
UDW83
Cloud Gateways70
Dream Machines70
Dream Routers70
Dream Wall70
ENVR73
ENVR-Core73
UCK73
UCK-Enterprise73
UCKP73
UNAS-273
UNAS-473
UNAS-Pro73
UNAS-Pro-473
UNAS-Pro-873
UNVR73
UNVR-G273
UNVR-G2-Pro73
UNVR-Instant73
UNVR-Pro73
Cloud Keys60
Enterprise Firewall Core60
Enterprise Fortress Gateway60
Enterprise Video Recorders60
Network Video Recorders60
Network Attached Storage50
UniFi Network Application50
UniFi Protect Application50
Express41
UniFi Access Application30
UniFi Talk Application30

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-349102026-06-2310.099.7CRITICAL
CVE-2026-349092026-06-2310.099.2CRITICAL
CVE-2026-349082026-06-2310.099.7CRITICAL
CVE-2010-53302022-04-1598.3

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2010-53302022-05-061566
CVE-2026-349082026-06-2654
CVE-2026-349092026-06-2654
CVE-2026-349102026-06-2654

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.