Robot Controller Flaw Can Alter Physical Process Behavior
This is unauthenticated code execution on the robot controller itself, not just another exposed web service. If Polyscope 5 is compromised, an attacker can affect robot behavior and firmware integrity, and a network-only fix may not undo changes already made on the machine.
CISA and Universal Robots say CVE-2026-8153 is an OS command injection flaw in the Polyscope 5 Dashboard Server interface. It affects Polyscope 5 versions before 5.25.1, and Universal Robots has released 5.25.1 as the fixed version.
For manufacturing and critical infrastructure operators, the risk is persistent compromise of equipment that directly drives physical processes. That makes patch status and device integrity more important than treating this as a routine host hardening issue.