HomeSecurityUniversal Robots PolyScope 5: Critical vulnerability affects robots

Universal Robots PolyScope 5: Critical vulnerability affects robots

A particularly serious security flaw has been identified in PolyScope 5, the software used in Universal Robots, causing widespread concern in the industrial cybersecurity community. The vulnerability, codenamed CVE-2026-8153, was rated with a CVSS score of 9.8, making it one of the most critical threats to industrial automation systems.

Universal Robots PolyScope 5

According to the technical information released, the issue affects all versions prior to PolyScope 5.25.1 and allows a remote attacker to execute arbitrary commands directly on the robot's operating system. All that is required is access to the network port of the Dashboard Server, a management mechanism used to remotely control and monitor robots.

Universal Robots PolyScope 5: How the command injection vulnerability works

The security vulnerability is related to incomplete input data filtering. The Dashboard Server accepts commands from the user and forwards them to the underlying operating system without properly isolating special characters or malicious payloads.

See also: KnowledgeDeliver LMS: Vulnerability allows RCE attacks

This allows an attacker to “inject” their own commands into the data sent to the robot. Once the system accepts these commands, it executes them with full administrator privileges, essentially giving the attacker complete control of the device.

On a practical level, such an attack could allow for the alteration of settings, the installation of malware, the disruption of production functions, or even the manipulation of the behavior of the robot itself.

The vulnerability was discovered by Vera Mens of Claroty Team82, while the disclosure process was carried out in collaboration with CISA and CERT/CC through the VINCE platform.

Collaborative robots at the center of cyberattacks

So-called collaborative robots or cobots are increasingly used in factories, warehouses and production lines, as they are designed to work alongside people. Unlike traditional industrial robots that operate isolated within protected spaces, cobots interact directly with personnel.

Universal Robots PolyScope 5: Critical vulnerability affects robots

This is what makes such vulnerabilities particularly dangerous. A compromised robot not only poses a threat to data or corporate systems, but potentially to the physical safety of employees as well.

Security experts warn that in the event of a complete breach, an attacker could movements, speeds or safety functions the robot's, creating unpredictable and dangerous situations within an industrial environment.

Although there are currently no known public attacks actively exploiting this vulnerability, the nature of the vulnerability is considered extremely concerning.

The importance of network isolation in factories

Universal Robots clarified that its products are not designed to be directly accessible from the internet. In most cases, corporate firewalls block external access to the Dashboard Server.

See also: Wireshark 4.6.6 fixes ROHC Parser vulnerabilities

However, the real problem lies in internal corporate networks. If a workstation or server within the same industrial environment is compromised through phishing, ransomware, or other attack, then the attacker can relatively easily move laterally towards the robot.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Researchers point out that many factories still operate with inadequate network segmentation, allowing critical OT systems to communicate directly with shared office IT networks. This significantly increases the risk of a cyberattack spreading.

The company called on all customers and integrators to immediately install PolyScope version 5.25.1 or later, as the available patch fully fixes the problem.

Universal Robots PolyScope 5: Critical vulnerability affects robots

Cybersecurity is becoming a critical issue for robotics

The Universal Robots case highlights a new reality for the automation industry: robots are no longer isolated machines, but connected digital systems that can be targeted by cybercriminals.

See also: Ghost CMS vulnerability: 700+ sites compromised and ClickFix attacks

As “smart” production lines, Industrial IoT networks, and automated facilities become the norm, cyberattacks in the industrial sector are expected to increase significantly in the coming years.

Organizations must now treat robots with the same seriousness they treat servers, cloud infrastructure , and corporate endpoints. Otherwise, even a seemingly simple command injection vulnerability can become a serious threat to production, data, and – in extreme cases – human safety.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS