CISA Catalog Update: Four Critical Vulnerabilities Under Active Exploitation Demand Urgent Patching
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation. The Lantronix EDS5000's code injection flaw allows attackers root-level command execution through authentication bypass. Ubiquiti UniFi OS servers face three severe vulnerabilities: improper access control, path traversal, and input validation issues, enabling unauthorized system changes and file access. Immediate patching is crucial for federal agencies under BOD 26-04, while all organizations are urged to prioritize these high-risk fixes.
Summary
The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) Catalog with four new entries, reflecting active exploitation in critical systems. These vulnerabilities affect both Lantronix EDS5000 devices and Ubiquiti UniFi OS servers, posing significant risks to federal agencies and private organizations alike. The inclusion of these vulnerabilities underscores the urgency for immediate remediation efforts.
What happened
CISA's addition of four new vulnerabilities to its KEV Catalog highlights ongoing exploitation threats. CVE-2025-67038 targets Lantronix EDS5000 devices, exploiting a code injection vulnerability in the HTTP RPC module. This flaw allows attackers to execute arbitrary OS commands with root privileges by injecting malicious input into the username parameter during authentication failures.
Ubiquiti UniFi OS servers are affected by three critical vulnerabilities: CVE-2026-34908 (improper access control), CVE-2026-34909 (path traversal), and CVE-2026-34910 (input validation). These flaws collectively enable attackers with network access to make unauthorized changes, access sensitive files, and execute command injections.
Affected products and fixed versions
The vulnerabilities impact specific products from Lantronix and Ubiquiti:
| Vendor | Product | Vulnerability ID |
|---|---|---|
| Lantronix | EDS5000 | CVE-2025-67038 |
| Ubiquiti | UniFi OS Server | CVE-2026-34908 |
| Ubiquiti | UniFi OS Server | CVE-2026-34909 |
| Ubiquiti | UniFi OS Server | CVE-2026-34910 |
Exploitation status
All four vulnerabilities are listed in CISA's KEV Catalog, indicating evidence of active exploitation. This status necessitates immediate attention from affected organizations to mitigate potential security breaches.
Technical details
Lantronix EDS5000 (CVE-2025-67038)
The vulnerability lies in the HTTP RPC module's handling of authentication failures. The username parameter is concatenated directly with a shell command without sanitization, allowing attackers to inject arbitrary commands executed with root privileges.
Ubiquiti UniFi OS Server
- Improper Access Control (CVE-2026-34908): Attackers can exploit this vulnerability to make unauthorized changes to the system.
- Path Traversal (CVE-2026-34909): This flaw allows attackers to access files on the underlying system, potentially leading to account manipulation.
- Improper Input Validation (CVE-2026-34910): Attackers can execute command injections by exploiting this vulnerability.
Why this matters for defenders
For federal agencies, BOD 26-04 mandates prioritizing the remediation of these high-risk vulnerabilities on publicly exposed assets. All organizations are encouraged to adopt risk-based vulnerability management practices and prioritize patching these critical flaws to prevent exploitation.
What remains unclear
While the vulnerabilities and their impacts are well-documented, specific details about ongoing attacks or affected entities remain undisclosed. Organizations should monitor for any updates from CISA and vendor advisories.
Defender guidance
- Immediate Patching: Apply patches as soon as they become available for all affected products.
- Network Monitoring: Enhance monitoring of network traffic to detect unusual activities that may indicate exploitation attempts.
- Access Controls: Review and strengthen access controls, especially for network devices like UniFi OS servers.
- Regular Audits: Conduct regular security audits to identify and mitigate potential vulnerabilities before they can be exploited.
Organizations must act swiftly to address these critical vulnerabilities and protect their systems from potential threats.
Sources
- https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog
- http://lantronix.com
- http://eds5000.com
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
- https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
- https://www.cve.org/CVERecord?id=CVE-2025-67038
