The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The additions cover one flaw in Lantronix EDS5000 device servers and three flaws in Ubiquiti UniFi OS.
Placement in the KEV Catalog means CISA has verified these flaws are being exploited in the wild, and under Binding Operational Directive (BOD) 26-04 federal civilian agencies must prioritize remediation of high-risk KEV entries on publicly exposed assets.
Key takeaways
- CISA added four actively exploited vulnerabilities to the KEV Catalog.
- The flaws affect Lantronix EDS5000 (CVE-2025-67038) and Ubiquiti UniFi OS (CVE-2026-34908, -34909, -34910).
- The UniFi OS issues cover improper access control, path traversal, and improper input validation.
- BOD 26-04 requires FCEB agencies to prioritize rapid remediation of high-risk KEV vulnerabilities on exposed assets.
- CISA encourages all organizations — not just federal agencies — to prioritize these fixes.
Affected
What happened
CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after determining they are being actively exploited by threat actors. The KEV Catalog is a curated list of flaws with confirmed real-world exploitation evidence and clear remediation guidance.
The newly listed vulnerabilities span two vendors: Lantronix and Ubiquiti. One affects the Lantronix EDS5000 device server, while the other three affect Ubiquiti UniFi OS.
- CVE-2025-67038 — Lantronix EDS5000 Code Injection Vulnerability
- CVE-2026-34908 — Ubiquiti UniFi OS Improper Access Control Vulnerability
- CVE-2026-34909 — Ubiquiti UniFi OS Path Traversal Vulnerability
- CVE-2026-34910 — Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Four CVEs added based on evidence of active exploitation
- Affected vendors: Lantronix and Ubiquiti
Why it matters
CISA notes that these vulnerability types are frequent attack vectors for malicious cyber actors and pose significant risk to the federal enterprise. KEV inclusion is a strong signal for prioritization: it confirms attackers are already using the flaw, rather than flagging a theoretical risk.
Binding Operational Directive (BOD) 26-04, "Prioritizing Security Updates Based on Risk," establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. It requires agencies to prioritize rapid remediation of high-risk KEV vulnerabilities on publicly exposed assets that grant total control of the asset after exploitation, while deferring lower-risk items.
Not just for federal agencies
BOD 26-04 applies only to FCEB agencies, but CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog entries.
The flaws in context
The Lantronix EDS5000 entry is described as a code injection vulnerability. Device servers like the EDS5000 bridge serial devices to IP networks and are commonly deployed in industrial and operational environments, where exposure can carry outsized consequences.
The three Ubiquiti UniFi OS entries cover distinct weakness classes — improper access control (CVE-2026-34908), path traversal (CVE-2026-34909), and improper input validation (CVE-2026-34910). UniFi OS underpins Ubiquiti's networking and management appliances used broadly across SMB and enterprise networks.
CISA's catalog entries do not, in this notice, detail CVSS scores, specific affected versions, or exploitation mechanics; administrators should consult each vendor's advisory for version-specific fix guidance.
What administrators should do
- Inventory environments for Lantronix EDS5000 devices and Ubiquiti UniFi OS appliances.
- Check each vendor's advisory for the specific fixed versions and apply updates.
- Prioritize any affected assets that are publicly exposed or grant significant control after compromise.
- Where BOD 26-04 applies, follow its expectations for checking whether threat actors compromised the system before the patch was applied.
Report exploitation
Organizations aware of an exploited vulnerability not yet in the KEV Catalog can submit it via CISA's KEV Nomination Form. Submissions require a CVE ID, evidence of exploitation, and clear mitigation guidance.
Impact & actions
Four actively exploited vulnerabilities in Lantronix EDS5000 and Ubiquiti UniFi OS now carry federal remediation obligations and serve as prioritization signals for all organizations.
Security: Confirmed real-world exploitation increases the likelihood of compromise for unpatched, internet-exposed devices.
Recommended actions · High urgency
- 1Identify affected Lantronix EDS5000 and Ubiquiti UniFi OS assets
- 2Apply vendor-recommended updates and prioritize exposed assets
- 3For FCEB agencies, remediate per BOD 26-04 requirements
Technical details
- CVEs
- CVE-2025-67038, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910
- Exploitation
- Exploited in the wild
Mitigations
- Apply vendor updates for affected Lantronix EDS5000 and Ubiquiti UniFi OS products
- Prioritize remediation of publicly exposed assets
Response
Authorities
Customer guidance
CISA advises organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities; FCEB agencies must follow BOD 26-04.
FAQ
What did CISA add to the KEV Catalog?
CISA added four actively exploited vulnerabilities: CVE-2025-67038 (Lantronix EDS5000 code injection) and CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 (Ubiquiti UniFi OS improper access control, path traversal, and improper input validation).
Does this only affect federal agencies?
BOD 26-04 remediation requirements apply only to Federal Civilian Executive Branch agencies, but CISA encourages all organizations to prioritize remediation of KEV Catalog vulnerabilities.
What is BOD 26-04?
Binding Operational Directive 26-04, 'Prioritizing Security Updates Based on Risk,' requires FCEB agencies to prioritize rapid remediation of high-risk KEV vulnerabilities on publicly exposed assets that grant total control after exploitation.
How can I report an exploited vulnerability to CISA?
Use CISA's KEV Nomination Form. Submissions must include a CVE ID, evidence of exploitation, and clear mitigation guidance.
The bottom line
CISA added four actively exploited vulnerabilities — one in Lantronix EDS5000 and three in Ubiquiti UniFi OS — to its KEV Catalog.
What happens next
What to do






