Vulnerabilities & Exploits · IoT / OT Attack

Robot Controller Flaw Can Alter Physical Process Behavior

This is unauthenticated code execution on the robot controller itself, not just another exposed web service. If Polyscope 5 is compromised, an attacker can affect robot behavior and firmware integrity, and a network-only fix may not undo changes already made on the machine.

CISA and Universal Robots say CVE-2026-8153 is an OS command injection flaw in the Polyscope 5 Dashboard Server interface. It affects Polyscope 5 versions before 5.25.1, and Universal Robots has released 5.25.1 as the fixed version.

For manufacturing and critical infrastructure operators, the risk is persistent compromise of equipment that directly drives physical processes. That makes patch status and device integrity more important than treating this as a routine host hardening issue.

3 sources · May 20

CVE-2026-8153

NVD KEV

CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 2% (76th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-20

Every edition of this story: Robot Controller Flaw Can Alter Physical Process Behavior

More from today