CVE-2026-8153Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 9 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 21 signals
  • Disclosure: 13 classified signals
  • Peaked 5d ago at 9 mentions (2026-05-19); latest day: 2
  • 24 total mentions across 9 days

Deep dive

Activity timeline24 mentions / 9d
02579Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-15: 2Mentions · 2026-05-19: 9Mentions · 2026-05-20: 4Mentions · 2026-05-21: 3Mentions · 2026-05-22: 1Mentions · 2026-05-31: 1Mentions · 2026-06-13: 2PoC Mentioned / Linked · 2026-05-19: 2PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-21: 1Exploit Tool / Code · 2026-05-19: 1Active Exploitation · 2026-05-19: 3Active Exploitation · 2026-05-20: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-19: 4Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 8Technical Details · 2026-05-20: 4Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-13: 205-0805-0905-1505-1905-2005-2105-2205-3106-13
Signal classification5 categories
Disclosure
1354.2%
Active Exploitation
416.7%
Patch
312.5%
General
312.5%
PoC
14.2%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-081
Patch1
2026-05-091
Disclosure1
2026-05-152
Disclosure1General1
2026-05-199
Active Exploitation3Disclosure4General1Patch1
2026-05-204
Active Exploitation1Disclosure3
2026-05-213
Disclosure1Patch1PoC1
2026-05-221
Disclosure1
2026-05-311
General1
2026-06-132
Disclosure2
Full discourse20 posts
  • Claroty@Claroty
    General

    📰 "However, Vera Mens (@V3rochka), the @Claroty security researcher credited with finding and reporting CVE-2026-8153, noted that cobots made by Universal Robots have a control box with an Ethernet port that can be used on demand." | via @SecurityWeek https://hubs.li/Q04jkslS0

    Post summary

    The post notes that researcher Vera Mens identified CVE-2026-8153 and observed that Universal Robots cobots have an Ethernet‑capable control box, but it offers no PoC, exploit, patch, or evidence of active exploitation.

    010100122
    4.3K followersView on X
  • PurpleOps@PurpleOps_io
    PoC

    Unauthenticated RCE on Universal Robots PolyScope 5 (CVE-2026-8153, CVSS 9.8). Cobot vendors have been treated as IT vulnerabilities; this one is closer to a safety incident. Walkthrough: https://purple-ops.io/blog/cve-2026-8153-universal-robots-rce

    Post summary

    The post announces a critical RCE (CVE‑2026‑8153) in Universal Robots PolyScope 5, linking to a walkthrough that likely contains a proof‑of‑concept.

    00062480
    605 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 CVE-2026-8153 affects Universal Robots PolyScope: an OS command injection in the Dashboard Server interface can let an unauthenticated attacker execute code on the robot OS. Patch to PolyScope 5.21.1+ and restrict access to port 29999. #CVE #CyberSecurity #ICS #OTSecurity https://nvd.nist.gov/vuln/detail/CVE-2026-8153

    Post summary

    CVE-2026-8153 is an OS command injection in Universal Robots PolyScope that permits unauthenticated code execution, mitigated by upgrading to PolyScope 5.21.1+ and restricting access to port 29999.

    0003075
    1.7K followersView on X
  • ransomNews@ransomnews
    Disclosure

    🚨 Critical robot flaw exposes industrial production lines to remote takeover CVE-2026-8153 allows unauthenticated remote code execution on #UniversalRobots controllers, exposing automated factory fleets to potential disruption and sabotage. 🔗 read more: https://www.securityweek.com/critical-vulnerability-exposes-industrial-robot-fleets-to-hacking/ #ransomNews #cybersecurity

    Post summary

    The post announces a newly disclosed CVE (CVE‑2026‑8153) that permits unauthenticated remote code execution on Universal Robots controllers, posing a significant threat to industrial automation, but does not provide an exploit, PoC, or patch details.

    00020244
    3.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Summary The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.  The post Critical Vulnerability Exposes Industrial Robot Fleets to Hacking appeared first on SecurityWeek.

    Post summary

    The post discloses that CVE-2026-8153 allows OS command injection on Universal Robots PolyScope 5 and provides only basic vulnerability details without PoC, patch, or evidence of active exploitation.

    1000027
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.  The post Critical Vulnerability Exposes Industrial Robot Fleets to Hacking appeared first on SecurityWeek.

    Post summary

    CVE-2026-8153 is an OS command injection vulnerability in Universal Robots PolyScope 5, reported by SecurityWeek; no evidence of exploit availability, active use, or patch status is provided.

    1000027
    267 followersView on X
  • Proficio@proficioinc
    Patch

    Patch Now: Critical Flaw (CVE-2026-8153) in OT Robot OS Gives Attackers Control via @DarkReading #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://www.darkreading.com/ics-ot-security/patch-now-critical-flaw-ot-robot-os

    Post summary

    The tweet alerts that a critical flaw (CVE‑2026‑8153) exists in OT Robot OS and urges patching, but it lacks detailed technical or exploit information.

    00010102
    1.0K followersView on X
  • Cyber_Lens@Aiz_Cyber
    Disclosure

    🚨 Critical flaw in industrial robots could enable remote takeover 🤖⚠️ CVE-2026-8153 lets attackers execute commands on Universal Robots controllers 🔥 Flat OT networks raise fleet-wide compromise risk 👇 #aiz_cyber #CVE #ZeroDay #PatchNow https://t.co/2SAfTgnjuM

    Post summary

    A critical vulnerability (CVE-2026-8153) in Universal Robots controllers that could enable remote command execution has been disclosed, underscoring risks across OT networks, but no active exploitation or PoC details are provided.

    0001055
    34 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-8153 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post merely announces a critical CVE with its CVSS score and severity, offering no deeper technical, exploit, or mitigation details.

    1000038
    226 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Universal Robotsの産業用協働ロボットに重大な脆弱性、CVE-2026-8153で認証不要のOSコマンド実行の恐れ https://rocket-boys.co.jp/security-measures-lab/universal-robots-cve-2026-8153-rce-vulnerability/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Universal Robots industrial collaborative robots are reported to have a critical unauthenticated OS command execution vulnerability (CVE-2026-8153), as highlighted in an online security post.

    00000149
    407 followersView on X
  • Tobibur Rahman@tobi8ur
    Disclosure

    SecurityWeek reports CVE-2026-8153 in Universal Robots PolyScope 5 can be exploited for OS command injection and potentially compromise entire cobot fleets. Industrial automation is great until the robot arm also accepts creative remote input. #Robotics #Cybersecurity

    Post summary

    SecurityWeek reports that CVE-2026-8153 in Universal Robots PolyScope 5 permits OS command injection, possibly enabling attackers to compromise entire cobot fleets.

    0000064
    79 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-8153 to achieve unauthenticated remote code execution on Universal Robots PolyScope 5 systems. The command injection flaw enabled privilege escalation and lateral movement across OT networks. Runtime segmentation helps contain such post-compromise activity in industrial environments. #OTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/universal-robots-cve-2026-8153-command-injection

    Post summary

    Attackers exploited CVE-2026-8153 via command injection to achieve unauthenticated remote code execution on Universal Robots PolyScope 5 systems, enabling privilege escalation and lateral movement across OT networks. The event demonstrates active exploitation with no mention of patches or a PoC.

    0000061
    1.9K followersView on X
  • Rory J. Bernier@RoryCrave
    Disclosure

    CVE-2026-8153: Command Injection in the PolyScope 5 Dashboard Server https://www.universal-robots.com/articles/ur/cybersecurity/cve-2026-8153-command-injection-in-the-polyscope-5-dashboard-server/

    Post summary

    The text announces CVE‑2026‑8153 as a command‑injection flaw in the PolyScope 5 Dashboard Server, but does not provide a PoC, exploit code, evidence of active exploitation, or patch information.

    0000043
    2.9K followersView on X
  • Tobibur Rahman@tobi8ur
    Disclosure

    SecurityWeek reports a critical CVE-2026-8153 flaw in Universal Robots PolyScope 5 can let unauthenticated attackers execute commands on industrial cobots. Industrial automation is great until the robot fleet also has a remote shell. #Cybersecurity #Robotics

    Post summary

    SecurityWeek announced a critical unauthenticated remote command execution flaw (CVE‑2026‑8153) in Universal Robots PolyScope 5 that could grant attackers a shell on industrial cobots, but no PoC, exploit code, or active exploitation reports are provided.

    0000052
    76 followersView on X
  • mot@kenebeii
    Active Exploitation

    【サイバーセキュリティ動向分析】 トレンドのセキュリティニュース(2026年5月19日時点) http://securityweek.com +2 Microsoft Exchange Serverのゼロデイ脆弱性(CVE-2026-42897)が野生で悪用中。パッチ準備中。 https://thehackernews.com/ https://www.securityweek.com/ https://www.security-next.com/184486 NGINXの18年ぶりクリティカル脆弱性(CVE-2026-42945など)が悪用開始・PoC公開。RCEやDoSのリスク。 https://thehackernews.com/ https://www.securityweek.com/exploitation-of-critical-nginx-vulnerability-begins/ https://www.security-next.com/184434 Cisco Catalyst SD-WAN Controllerの深刻脆弱性が積極悪用中。管理アクセス奪取の恐れ。 https://www.securityweek.com/ https://www.security-next.com/184451 Chromeのセキュリティ更新(79件脆弱性修正、14件クリティカル)。 https://www.security-next.com/184460 OpenClaw / Claw Chainの複数脆弱性連鎖でサンドボックス脱出・バックドア設置可能。 https://www.securityweek.com/ 7-Elevenデータ侵害確認(ShinyHuntersがSalesforceレコード60万件超主張)。 https://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/ Grafana Labsコードベース侵害(漏洩トークン経由)。 https://www.securityweek.com/ Nx Console VS Code拡張機能がサプライチェーン攻撃でコンパイルされ、開発者資格情報窃取。 https://thehackernews.com/ Universal Robots PolyScope 5のクリティカル脆弱性(CVE-2026-8153)で産業ロボット艦隊がハッキングリスク。 https://www.securityweek.com/ SEPPMail Secure E-Mail Gatewayの複数脆弱性(RCE含む)。 https://thehackernews.com/ 供給チェーン攻撃多発(npmパッケージ、GitHub Actions、TanStackなど)。 https://thehackernews.com/ https://www.securityweek.com/ 主なトレンド: ゼロデイ/既知脆弱性の即時悪用加速(Exchange、NGINX、Cisco)。 サプライチェーン/拡張機能/オープンソースの侵害増加。 AI関連・OAuthフィッシングの進化。 http://thehackernews.com 詳細は上記URLから直接確認を。

    Post summary

    Several critical CVEs—including Microsoft Exchange, NGINX, and Cisco Catalyst—are actively exploited in the wild, PoCs have been released, and patches or mitigations are being prepared.

    00000146
    225 followersView on X
  • connect24h@connect24h
    Disclosure

    工場ロボット群がハッキングの標的に。Universal Robots PolyScope5でOS Command Injection(CVE-2026-8153)が発見。遠隔からRCEが可能でOT環境への波及リスクが深刻。Attack Surfaceは工場・物流全域に拡大中。https://tinyurl.com/25zehp5v #ICS #OTSecurity

    Post summary

    Universal Robots PolyScope5 has a disclosed OS Command Injection vulnerability (CVE-2026-8153) that permits remote code execution and raises significant OT security concerns.

    00000146
    2.8K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Universal Robots patched CVE-2026-8153, a 9.8 command injection flaw in PolyScope 5 Dashboard Server that could let attackers run commands on cobot controllers and spread across poorly segmented OT fleets. #UniversalRobots #PolyScope5 #CVE20268153 https://ift.tt/bk4ignp

    Post summary

    Universal Robots issued a patch for CVE‑2026‑8153, a command injection flaw in PolyScope 5 Dashboard Server that could let attackers run commands on cobot controllers, mitigating the risk to OT fleets.

    00000136
    4.3K followersView on X
  • ThreatAft@ThreatAft
    General

    🔐 CISA just issued an ICS advisory for CVE-2026-8153: an unauthenticated OS command injection in Universal Robots PolyScope 5 (CVSS 9.8). 🔗 https://threataft.com/articles/universal-robots-polyscope-cve-2026-8153-command-injection #CyberSecurity #ThreatIntel #UR #IndustrialSecurity #Cobots #CVE20268153 #infosec #OTSecurity

    Post summary

    A CISA advisory was released for CVE-2026-8153, detailing an unauthenticated OS command‑injection vulnerability in Universal Robots' PolyScope 5 with a CVSS score of 9.8, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    00000328
    25 followersView on X
  • mot@kenebeii
    Active Exploitation

    【サイバーセキュリティ動向分析】 トレンドのセキュリティニュース(2026年5月時点) Microsoft Exchange Serverゼロデイ脆弱性(CVE-2026-42897) が野生で積極的に悪用中。XSS関連のスプーフィング脆弱性で、パッチ準備中。 https://thehackernews.com/ https://www.security-next.com/184486 nginxのクリティカル脆弱性 が悪用開始。デフォルト設定でDoS、ASLR無効時はRCE可能。PoCも公開。 https://www.securityweek.com/exploitation-of-critical-nginx-vulnerability-begins/ https://www.security-next.com/184434 ソフトウェアサプライチェーン攻撃活発化(Mini Shai-Huludなど)。npmパッケージ( @antv 系、echarts-for-reactなど)やGitHub Actionsが侵害され、資格情報窃取やワーム拡散。 https://thehackernews.com/ https://www.securityweek.com/ OpenClawの4つの脆弱性チェーン(Claw Chain)でサンドボックス脱出・永続的バックドア可能。 https://www.securityweek.com/ Universal Robots PolyScope 5のクリティカル脆弱性(CVE-2026-8153) で産業用ロボット群にOSコマンドインジェクションのリスク。 https://www.securityweek.com/ Ivanti、Fortinet、Cisco Catalyst SD-WAN、SAPなど複数ベンダーの重要脆弱性 パッチリリース(RCE/SQLiなど、一部すでに悪用)。 https://www.security-next.com/ https://www.securityweek.com/ 7-Elevenデータ侵害確認(ShinyHunters要求後)。Salesforce記録60万件超窃取主張。Grafanaも侵害確認。 https://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/ https://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/ AI関連トレンド:Anthropic Mythos/OpenAI DaybreakなどのAIツールによる脆弱性発見加速、AI生成レポート洪水、AI支援攻撃増加。 https://www.cybersecuritydive.com/ https://cyberscoop.com/ 日本国内注目:Chrome/Edge更新、Exchange/Cisco脆弱性、ランサム被害事例(損害調査法人など)。 https://www.security-next.com/ これらはSecurityWeek、The Hacker News、Security NEXTなどの最新ヘッドラインに基づく主なトレンドです。詳細は上記URLを直接確認してください。 CVE-2026-42897の詳細 サプライチェーン攻撃対策 URLをリスト形式で

    Post summary

    The text highlights several critical vulnerabilities that are currently being exploited in the wild, including a zero‑day affecting Microsoft Exchange (CVE-2026-42897) and a critical nginx flaw, with PoC code available and vendor patches in progress.

    00000134
    225 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVE-2026-8153 in Universal Robots PolyScope 5: confirmed exploitation in the wild, allowing hackers to inject OS commands into industrial robot fleets. This could disrupt operations globally. Patch now. #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/CgUmXWTvJU

    Post summary

    The tweet reports that CVE-2026-8153 in Universal Robots PolyScope 5 is actively exploited to inject OS commands into robot fleets, urging immediate patching to mitigate potential operational disruptions.

    0000052
    64 followersView on X

Explore more