Junglewise Threat Intelligence

CVE-2026-77555: Ubiquiti UniFi Gateway out-of-bounds write denial of service

CVE-2026-77555 · Severity: high · CVSS 7.5 · Published 2026-09-22

Technologies: Ubiquiti UniFi Gateway. Vendors: Ubiquiti.

Executive brief

Ubiquiti UniFi gateway devices contain an out-of-bounds memory writing flaw that allows a network-connected attacker to crash the gateway and disrupt network connectivity. An attacker with access to the network can trigger this vulnerability to cause a denial of service, taking the device offline and potentially disrupting business operations that depend on the gateway for internet access or routing.

Technical details

An out-of-bounds write vulnerability exists in certain UniFi gateway devices that allows an attacker with network access to write data beyond allocated memory boundaries. By exploiting this memory corruption issue, an attacker can crash the gateway process or the device itself, resulting in denial of service. The vulnerability requires network access but no authentication.

Affected products

  • Ubiquiti UniFi Gateway

Timeline

  • 2026-09-22: disclosed

References

Related threats