UniFi This Week: Protect CVEs and Travel Router LR Launch
News & ArticlesNetworking

UniFi This Week: Protect CVEs and Travel Router LR Launch

JMJim MazzarellaCEO & Managing Partner September 7, 2026 1 min read

Ubiquiti issued critical security CVEs affecting UniFi Protect, while rolling out initial firmware for the UniFi Travel Router Long-Range and SuperLink Recessed Entry Sensor.

The first week of September brought important security disclosures alongside new hardware firmware releases within the Ubiquiti ecosystem. Most notably, two critical command injection vulnerabilities affecting UniFi Protect were indexed for remediation, while new firmware distributions marked the emergence of new network and physical security hardware. Facilities and IT leaders should prioritize verifying their Protect deployments and review the latest hardware options.

Security Advisories

  • UniFi Protect Command Injection Vulnerabilities (CVE-2026-77533 & CVE-2026-77548): Disclosed with critical CVSS base scores of 9.9, these improper input validation flaws allow an attacker with local network access and low privileges to execute command injection on the host surveillance console. For commercial, healthcare, and hospitality operators, this reinforces the urgent operational requirement to isolate physical security consoles onto dedicated, access-controlled management VLANs and maintain current software builds.

UniFi Network

  • UniFi Travel Router Long-Range Firmware 6.6.117: Ubiquiti released initial hardware firmware for the UniFi Travel Router Long-Range, establishing baseline compatibility requiring UniFi mobile app versions iOS 10.37.1 or Android 10.39.7. For distributed enterprises and executive hospitality staff, this introduces a managed, high-coverage portable gateway option for secure remote tunneling back to corporate infrastructure.

UniFi Protect

  • UniFi Protect SuperLink Recessed Entry Sensor 1.0.1: Initial firmware support has been released for the USL-Entry-R recessed door and window sensor. For facility and security managers, concealed sensors allow discreet perimeter monitoring in design-sensitive hospitality spaces and access-controlled healthcare environments without visible hardware on door frames.
  • UniFi Protect Android 3.8.2: A maintenance release rolled out across Android endpoints to enhance the UniFi OS update process from mobile devices. This streamlines administrative oversight for security and facilities personnel managing site video infrastructure from mobile devices.

Nexus Communications Technology systematically evaluates all new UniFi hardware releases and firmware updates in our staging lab before pushing them into production client environments. Contact our engineering team today to schedule a comprehensive UniFi360 network and security assessment for your facility.

Share

Let's talk about your project.

Get a free assessment and proposal from the Nexus team — typically within one business day.