Independent · not affiliated with SpaceX or StarlinkParts prices checked

Farm gear & camerasPrimary sourceBackgroundIndependent, not affiliated with SpaceX

UniFi Protect flaw let someone on the local network reach Protect cameras; fixed in version 6.2.72

On 2026-01-05 a high-severity flaw in the UniFi Protect app (6.1.79 and earlier) was published. Someone on your local network could reach a camera. Update to 6.2.72 or later.

Announced or first reported
Effective
Published
Last updated
Card: UniFi Protect application 6.1.79 and earlier has a discovery-protocol flaw (CVE-2026-21633, CVSS 8.8 High) that lets someone on the local network reach a Protect camera. Fix: update to 6.2.72 or later.

What changed

The US National Vulnerability Database published CVE-2026-21633 on 2026-01-05. Its description, supplied through Ubiquiti’s Security Advisory Bulletin 058: “A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earlier).”

The listed fix is to update the UniFi Protect application to version 6.2.72 or later. The flaw is scored 8.8 (High) under CVSS 3.1. The attack vector is the adjacent network, meaning someone already on your local network, not someone on the open internet.

Old and new, with the source date
ItemBeforeAfterSource date
UniFi Protect application6.1.79 and earlier: discovery-protocol flaw (CVE-2026-21633)Fixed in 6.2.72 or later2026-01-05
Severityn/aCVSS 3.1 score 8.8, High; attacker must be on the adjacent (local) network2026-01-05

Who it affects

Farms running Ubiquiti UniFi Protect cameras with the Protect application on a UniFi console, at version 6.1.79 or earlier. Cameras from other brands, and Ubiquiti’s airMAX bridge radios, aren’t named in the advisory.

What it means for your setup

“Adjacent network” matters more on a farm than it sounds. A farm network often stretches across several buildings: a bridge to the barn, an access point in the shop, maybe Wi-Fi a farm hand or a neighbor uses. Anyone who can join that network could, on an unpatched system, reach a Protect camera.

Two habits limit this kind of risk for any brand. First, keep camera software updated. Second, keep cameras on their own network segment, away from guest Wi-Fi, and lock down any wireless bridge with a strong key so strangers can’t join it. Remote viewing over Starlink’s CGNAT isn’t affected either way; see remote viewing behind CGNAT.

What to do now

  • Open the UniFi Protect application and check its version. If it is 6.1.79 or earlier, update to 6.2.72 or later, per the advisory.
  • Turn on automatic updates for Protect if your console supports it.
  • Check who can join the network your cameras are on. Use a separate guest Wi-Fi for visitors and workers.

What stays the same

  • How UniFi Protect cameras connect for remote viewing.
  • Starlink’s CGNAT, which blocks inbound connections from the internet by default.
  • Ubiquiti airMAX bridge radios, which the advisory doesn’t mention.

What we don’t know yet

  • Whether this flaw was ever used against real systems. The CISA coordinator entry on the NVD record lists exploitation as “none” as of 2026-01-05.
  • We couldn’t load Ubiquiti’s bulletin page itself; the quote comes from the NVD record, which links it.

Sources

  1. CVE-2026-21633 detail, NIST National Vulnerability Database. Source date: 2026-01-05. Primary. Retrieved 2026-10-06.
    “Update your UniFi Protect Application to Version 6.2.72 or later.”
  2. Security Advisory Bulletin 058, Ubiquiti Community. Source date: linked from the NVD record; page did not load for us. Primary. Retrieved 2026-10-06.

Corrections

No corrections since publication. Spotted an error? Tell us.