Published Friday, October 09, 2026 at 12:19 AM PT

BLUF: The Rack 14 UniFi gateway (UDM-Pro) logged and blocked an inbound exploit-class IPS event associated with 192.168.1.1 at Oct 9, 00:17:50. The log shows no successful compromise. The source and the specific exploit are not identified in available data. Status: DEVELOPING, monitoring, unconfirmed beyond the block.
DETAILS
- Log entry: “IPS: exploit,” timestamp Oct 9 00:17:50, host Rack14-UDMPro, process ubios-udapi-server[1326961].
- Threat type: IPS. Action: blocked. Direction: inbound. Associated address: 192.168.1.1.
- Source address recorded as “unknown.” The provided log excerpt includes no CVE, signature ID, or exploit name.
- Nova memory returned several exploit and CVE entries, but none is tied to this event in the available material. No link is established.
IMPACT
- Scope: the gateway at 192.168.1.1 and inbound traffic on its path.
- Confirmed: an exploit-class attempt was detected and blocked.
- Not confirmed: whether the attempt was aimed only at the gateway or at other hosts, whether any part of it reached a target before the block, and who was behind it.
- No evidence in the material of lateral movement, data access, or persistence.
RECOMMENDED ACTIONS
- Pull full IPS event detail from the UniFi/UDM-Pro console: signature ID, CVE if mapped, source IP, protocol, and destination port. This step resolves most open questions.
- Review gateway logs around 00:17 on Oct 9 for other IPS events and for any inbound sessions that were allowed.
- Confirm UniFi OS and firmware are current, and that management interfaces are not reachable from the WAN.
- If a source IP is identified, consider a perimeter block and report it per local policy.
- Escalate to a confirmed incident if step 1 or 2 shows any successful inbound session or a matched exploit against a live service.
SOURCES
- UDM-Pro IPS log line: Rack14-UDMPro, ubios-udapi-server[1326961], Oct 9 00:17:50.
- Nova memory context, cited for background only and not linked to this event: SOC Prime advisory on CVE-2026-94127 (F5 BIG-IP APM); sploitus exploit listings for CVE-2024-29415, CVE-2013-4784, CVE-2026-103978, CVE-2026-102971, CVE-2026-31908, CVE-2026-88789, CVE-2018-0886, and CVE-2024-50961; prior Nova alert “Internal threat blocked” (2026-06-04).
Recent high-severity events at publish time:

