A particularly serious security flaw has been identified in PolyScope 5, the software used in Universal Robots, causing widespread concern in the industrial cybersecurity community. The vulnerability, codenamed CVE-2026-8153, was rated with a CVSS score of 9.8, making it one of the most critical threats to industrial automation systems.

According to the technical information released, the issue affects all versions prior to PolyScope 5.25.1 and allows a remote attacker to execute arbitrary commands directly on the robot's operating system. All that is required is access to the network port of the Dashboard Server, a management mechanism used to remotely control and monitor robots.
Universal Robots PolyScope 5: How the command injection vulnerability works
The security vulnerability is related to incomplete input data filtering. The Dashboard Server accepts commands from the user and forwards them to the underlying operating system without properly isolating special characters or malicious payloads.
See also: KnowledgeDeliver LMS: Vulnerability allows RCE attacks
This allows an attacker to “inject” their own commands into the data sent to the robot. Once the system accepts these commands, it executes them with full administrator privileges, essentially giving the attacker complete control of the device.
On a practical level, such an attack could allow for the alteration of settings, the installation of malware, the disruption of production functions, or even the manipulation of the behavior of the robot itself.
The vulnerability was discovered by Vera Mens of Claroty Team82, while the disclosure process was carried out in collaboration with CISA and CERT/CC through the VINCE platform.
Collaborative robots at the center of cyberattacks
So-called collaborative robots or cobots are increasingly used in factories, warehouses and production lines, as they are designed to work alongside people. Unlike traditional industrial robots that operate isolated within protected spaces, cobots interact directly with personnel.

This is what makes such vulnerabilities particularly dangerous. A compromised robot not only poses a threat to data or corporate systems, but potentially to the physical safety of employees as well.
Security experts warn that in the event of a complete breach, an attacker could movements, speeds or safety functions the robot's, creating unpredictable and dangerous situations within an industrial environment.
Although there are currently no known public attacks actively exploiting this vulnerability, the nature of the vulnerability is considered extremely concerning.
The importance of network isolation in factories
Universal Robots clarified that its products are not designed to be directly accessible from the internet. In most cases, corporate firewalls block external access to the Dashboard Server.
See also: Wireshark 4.6.6 fixes ROHC Parser vulnerabilities
However, the real problem lies in internal corporate networks. If a workstation or server within the same industrial environment is compromised through phishing, ransomware, or other attack, then the attacker can relatively easily move laterally towards the robot.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Researchers point out that many factories still operate with inadequate network segmentation, allowing critical OT systems to communicate directly with shared office IT networks. This significantly increases the risk of a cyberattack spreading.
The company called on all customers and integrators to immediately install PolyScope version 5.25.1 or later, as the available patch fully fixes the problem.

Cybersecurity is becoming a critical issue for robotics
The Universal Robots case highlights a new reality for the automation industry: robots are no longer isolated machines, but connected digital systems that can be targeted by cybercriminals.
See also: Ghost CMS vulnerability: 700+ sites compromised and ClickFix attacks
As “smart” production lines, Industrial IoT networks, and automated facilities become the norm, cyberattacks in the industrial sector are expected to increase significantly in the coming years.
Organizations must now treat robots with the same seriousness they treat servers, cloud infrastructure , and corporate endpoints. Otherwise, even a seemingly simple command injection vulnerability can become a serious threat to production, data, and – in extreme cases – human safety.
