Unas 2
Vendor:
First CVE: May 22, 2026 · Active for under a year
9
Total CVEs
More Total CVEs than 86% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 78% of tracked products
33.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Unas 2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2026
2 months ago
Most Recent CVE
Jul 2, 2026
25 days ago
CVE Severity & Scoring
Unas 29 CVEs
11%
56%
33%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34910CRITICAL A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | May 22, 2026 | 10.0 | 98 | YES | YES |
CVE-2026-34908CRITICAL A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | May 22, 2026 | 10.0 | 95 | YES | NO |
CVE-2026-34909CRITICAL A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat | May 22, 2026 | 10.0 | 94 | YES | NO |
CVE-2026-54402HIGH A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the hos | Jul 2, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-54404HIGH A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges withi | Jul 2, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-54401HIGH A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | Jul 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-54403HIGH A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS device | Jul 2, 2026 | 8.6 | 37 | NO | NO |
CVE-2026-34911HIGH A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that | May 22, 2026 | 7.7 | 34 | NO | NO |
CVE-2026-55110MEDIUM A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in | Jul 2, 2026 | 6.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
3 CVEs
33.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Unas 2
Top CWEs
Versions
No cataloged versions.