Unas Pro
Vendor:
First CVE: May 22, 2026 · Active for under a year
9
Total CVEs
More Total CVEs than 86% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 78% of tracked products
33.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Unas Pro over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2026
2 months ago
Most Recent CVE
Jul 2, 2026
24 days ago
CVE Severity & Scoring
Unas Pro9 CVEs
11%
56%
33%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34910CRITICAL A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | May 22, 2026 | 10.0 | 98 | YES | YES |
CVE-2026-34908CRITICAL A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | May 22, 2026 | 10.0 | 95 | YES | NO |
CVE-2026-34909CRITICAL A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat | May 22, 2026 | 10.0 | 94 | YES | NO |
CVE-2026-54402HIGH A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the hos | Jul 2, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-54404HIGH A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges withi | Jul 2, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-54401HIGH A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | Jul 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-54403HIGH A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS device | Jul 2, 2026 | 8.6 | 37 | NO | NO |
CVE-2026-34911HIGH A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that | May 22, 2026 | 7.7 | 34 | NO | NO |
CVE-2026-55110MEDIUM A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in | Jul 2, 2026 | 6.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
3 CVEs
33.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Unas Pro
Top CWEs
Versions
No cataloged versions.