Ubiquiti's SAB-067: 22 UniFi Vulnerabilities, Three Rated CVSS 10.0, and a Patch Cycle MSPs Can't Outrun Alone
Ubiquiti's latest security bulletin patches 22 UniFi vulnerabilities, three of them maximum severity. For MSPs managing UniFi fleets across dozens of client sites, the patch cycle takes days. Here's what to do while it runs.
What Happened
Ubiquiti published Security Advisory Bulletin SAB-067, patching 22 vulnerabilities across the UniFi ecosystem. Three of them carry a CVSS score of 10.0, the maximum severity rating a vulnerability can receive. The affected surface isn't a single product line either. It spans UniFi OS, UniFi camera firmware, and UniFi VoIP and phone systems, which means the exposure runs across network infrastructure, physical security devices, and communications gear at the same time.
The vulnerability types listed in the bulletin include command injection, authentication bypass, and privilege escalation. Put plainly: an attacker who finds an exposed management interface could potentially run commands, get past login controls, or climb from a low-privilege account to an administrative one, on devices that most organizations treat as set-and-forget infrastructure sitting quietly at the edge of the network.
This bulletin didn't stay inside the Ubiquiti community forum for long. It reached NHS England's cyber alert feed within days of release, which tells you something about how seriously the healthcare sector's own security teams are treating it. Independent outlets including BleepingComputer, SC Media, Field Effect, and GBHackers covered the advisory within 24 to 48 hours of publication. When that many independent trackers move on the same bulletin that fast, it's not noise. It's a signal that the exploitation window matters and everyone watching this space knows it.
Who's affected: any organization, and by extension any MSP, running UniFi controllers, access points, switches, cameras, or VoIP hardware anywhere in a managed environment. If UniFi shows up in your client inventory, this bulletin applies to you.
This Isn't Ubiquiti's First Critical Bulletin This Year
SAB-067 is notable for its severity, but it's not an isolated event. Ubiquiti issued SAB-047 in May 2025 and SAB-056 in October 2025, both addressing critical and high severity flaws in the UniFi product line. SAB-057 followed shortly after. That's four major bulletins inside roughly eighteen months, on a product family that sits at the network edge in thousands of MSP-managed environments.
The pattern matters more than any single bulletin. UniFi gear is popular precisely because it's affordable, centrally managed, and easy to deploy at scale, which is exactly why a single vulnerability class can ripple across an entire client base in one advisory. A vendor with a good bulletin cadence isn't a red flag. A vendor whose bulletins keep landing at CVSS 10.0 is a reminder that edge devices need the same patch discipline you'd apply to a domain controller, not the "we'll get to it next maintenance window" treatment they usually receive.
If your patch management process treats UniFi firmware as a quarterly chore, SAB-067 is the bulletin that should change that assumption.
What a Partner Should Actually Do About It
Start with inventory, not patching. You can't prioritize what you can't see. Pull a current list of every client site running UniFi OS, controllers, access points, cameras, or phones, and map each device to its current firmware version. If that list doesn't already exist in a form you trust, building it is today's task, not next week's.
Once you have the list, triage by severity and exposure, not by client alphabetically. The three CVSS 10.0 flaws go first, on every device that carries them, regardless of which client pays the highest retainer. Internet-facing management interfaces move to the front of the queue ahead of devices sitting behind a firewall with no external access, because the attack surface is different even when the underlying CVE is identical.
Here's the part that doesn't show up in the advisory: patching 22 CVEs across an entire UniFi fleet, across dozens of client sites, with change windows, testing, and rollback plans, takes days. Sometimes longer, depending on how distributed the fleet is and how much coordination each client relationship requires. That's not a criticism of any MSP's process. It's math. Twenty-two vulnerabilities times however many sites you manage, divided by however many technicians you have available this week, equals a patch cycle measured in days, not hours.
While that cycle runs, compensating controls matter. Restrict management interface access to known IP ranges wherever possible. Disable remote administration on devices that don't need it. Rotate admin credentials on UniFi controllers, especially any that have been in service long enough that you're not certain who's had access to them. None of this replaces patching. It buys the time patching needs.
Where Monitoring Closes the Gap Patching Can't Close Fast Enough
A patch cycle is a race against a window, and the window opens the moment a bulletin like SAB-067 goes public, because proof-of-concept exploit code tends to follow disclosure faster than most patch schedules can move. That gap, between "the fix exists" and "the fix is deployed everywhere it needs to be," is where exploitation actually happens.
This is the part of the problem that patching alone doesn't solve, and it's the part Vijilan's Global SOC is built to cover. ThreatRespond™, our Managed XDR service, ingests logs from network edge devices alongside endpoint and identity telemetry, so UniFi gear isn't a monitoring blind spot sitting outside the rest of your security stack. When an admin login pattern looks wrong for the account, time, or location involved, when an unusual sequence of requests hits a management interface, or when a device starts executing commands it has no legitimate reason to run, our analysts see it against the same timeline as everything else in the environment, and they can move to isolate the device the moment the behavior appears. Not after a follow-up headline confirms active exploitation. Not after the next bulletin references SAB-067 as the vulnerability that got used in the wild.
That pairing, patch cycle on one side and log-based detection and containment on the other, is what turns a 22-CVE bulletin from a fire drill into a manageable week. Your team runs the patch schedule. Our SOC watches the devices while that schedule runs, and again after it's done, because SAB-047, SAB-056, and SAB-067 are not going to be the last bulletin Ubiquiti issues this year.
For MSPs and MSSPs already carrying the patch workload for UniFi fleets, adding that monitoring layer doesn't mean adding headcount or a new console to babysit. Vijilan delivers it white-label, under your brand, and we never compete with our partners for their clients. The SOC work happens behind your name.
If you're weighing what that looks like for your stack, our MSP partner page walks through how the Global SOC integrates with the tools you're already running. Pricing questions go to our pricing page, since that's not something we're going to guess at here.
The Bottom Line
SAB-067 patches 22 real vulnerabilities, three of them as severe as CVSS scoring gets. The patch cycle across a UniFi fleet takes days. The exploitation window opens the moment the bulletin goes public. Closing that gap isn't a patching problem or a monitoring problem, it's both, running in parallel, on the same devices, watched by people who don't clock out when the change window ends.
Frequently asked questions
What is Ubiquiti's SAB-067 advisory?
SAB-067 is Ubiquiti's security bulletin patching 22 vulnerabilities across the UniFi ecosystem, including UniFi OS, camera firmware, and VoIP systems, with three of the flaws rated at the maximum CVSS score of 10.0.
Who is affected by the UniFi vulnerabilities in SAB-067?
Any organization running UniFi controllers, access points, switches, cameras, or VoIP hardware is potentially affected. For MSPs, that means checking every client site where UniFi gear is deployed, not just a single flagship environment.
How long does it take to patch a UniFi fleet against 22 CVEs?
For MSPs managing UniFi across multiple client sites, coordinating inventory, testing, change windows, and rollout across 22 CVEs typically takes days rather than hours, which is why compensating controls and monitoring matter during the patch cycle.
Does patching alone close the exposure window for SAB-067?
No. Proof-of-concept exploit activity often follows disclosure faster than fleet-wide patching can complete. Log-based monitoring on the affected devices covers the gap between disclosure and full remediation.
Is this the first time Ubiquiti has issued a critical UniFi bulletin?
No. Ubiquiti issued SAB-047 in May 2025 and SAB-056 in October 2025, both addressing critical or high severity UniFi flaws, making SAB-067 part of a recurring pattern rather than an isolated event.
See what 24/7 looks like when the SOC actually acts.
Book a 20-minute platform walkthrough: no slide deck, just the console.
Book a walkthrough →