Junglewise Threat Intelligence

CVE-2026-95861: Ubiquiti UniFi Gateway uncontrolled recursion denial of service

CVE-2026-95861 · Severity: high · CVSS 7.5 · Published 2026-09-22

Technologies: Ubiquiti UniFi Gateway. Vendors: Ubiquiti.

Executive brief

UniFi Gateway devices are network appliances that manage connectivity and routing for enterprise networks. An uncontrolled recursion flaw allows a network-connected attacker to crash the gateway, causing a complete outage of network services until the device is manually rebooted.

Technical details

An uncontrolled recursion vulnerability in certain UniFi Gateway firmware versions allows a network-accessible attacker to trigger excessive recursive function calls, exhausting stack resources and crashing the device. No authentication is required; the attack is triggered through specially crafted network packets. A successful exploit results in denial of service.

Affected products

  • Ubiquiti UniFi Gateway

Timeline

  • 2026-09-22: disclosed

References

Related threats