Sunday, October 4, 2026 Sign inSubscribe to The Brief →
Humanoid Threats

Security for the age of physical AI

Humanoid Robot Vulnerability Tracker

Every publicly disclosed vulnerability and security incident affecting humanoid robots, plus related legged and consumer robots, in one place. Each entry links to the original advisory or research. We update this tracker as new disclosures appear.

Last updated: October 4, 2026. Know of a disclosure we missed? Email info@humanoidthreats.com.

Humanoid robots

DisclosedRobotIDWhat it allowsSeverityFix status
Aug 27, 2026Unitree G1 EDUCVE-2026-76639Root code execution over the network through the robot's AI chatbot service. Researcher showed one hacked G1 could reach a second G1.Root accessNo fixed firmware publicly confirmed as of late Aug 2026
Aug 27, 2026Unitree G1 EDUCVE-2026-76640Root code execution over Bluetooth Low Energy from nearby, with no pairing.Root accessNo fixed firmware publicly confirmed as of late Aug 2026
Sep 26, 2025Unitree G1, H1 (also Go2, B2)CVE-2025-35027 ("UniPwn")Command injection while configuring Wi-Fi over BLE, leading to root command execution. Affected: G1 and H1 firmware 1.4.4 and earlier.7.3 HighAffected versions listed; update to later firmware
Sep 26, 2025Unitree G1, H1 (also Go2, B2)CVE-2025-60250Hardcoded encryption key and IV used to decrypt Bluetooth packet data.4.7 MediumAffects versions through Sep 20, 2025
Sep 2025Unitree G1No CVE (research)Security assessment reported hardcoded keys and telemetry sent to remote servers every few minutes without notifying the user. The vendor has said it does not collect private data without authorization.Privacy / data exposureDisputed by vendor

Quadrupeds, cobots and consumer robots

DisclosedRobotIDWhat it allowsSeverityFix status
May 8, 2026Universal Robots cobots (PolyScope 5)CVE-2026-8153Unauthenticated OS command injection in the Dashboard Server interface, giving full control of the robot's operating system.9.8 CriticalFixed in PolyScope 5.25.1
Mar 10, 2026Hookii Neomow mower, Hypershell X exoskeleton, HOBOT S7 Pro window cleanerMultiple (research)38 vulnerabilities found in about 7 hours by an AI-assisted research team, 30 rated Critical or High, including root access and control of connected devices through shared credentials.30 Critical/HighSee vendor advisories
Sep 26, 2025Unitree Go2, B2 quadrupedsCVE-2025-35027, CVE-2025-60250Same BLE Wi-Fi setup flaws as the G1 and H1 entries above. Affected: Go2 and B2 firmware 1.1.8 and earlier.7.3 High / 4.7 MediumUpdate to later firmware
Mar 28, 2025Unitree Go1 quadrupedCVE-2025-2894Undocumented backdoor allowing remote control through the CloudSail service for anyone with the right API key.6.6 MediumGo1 is discontinued; isolate or retire units

What the pattern shows

Most humanoid and legged-robot flaws so far share three entry points: Bluetooth and Wi-Fi setup, cloud and remote-control services, and AI assistant interfaces that reach the operating system. Several give full root access. Fix status is often unclear, so buyers should ask vendors directly which firmware version addresses each CVE. For the background, read Can humanoid robots be hacked? and our Unitree G1 CVE explainer. To protect a fleet, use the Humanoid Robot Security Checklist and find vendors in the security directory.

Sources

Get new robot vulnerabilities in your inbox every Thursday: subscribe to The Humanoid Threats Brief.

The Humanoid Threats Brief

The weekly briefing on humanoid robot security.

New vulnerabilities, incidents, standards and defenses, with why each one matters. Built for security teams, robotics engineers and the people buying humanoids.

  • Every claim sourced. We link the CVE, the paper or the regulator, not rumors.
  • 5-minute read. One email a week, every Thursday.
  • Free. No spam, unsubscribe in one click.

Check your inbox to confirm your subscription.

Something went wrong. Please try again.

Read a recent storyUnitree G1 Vulnerabilities Explained: CVE-2026-76639 and CVE-2026-76640 →
100% primary-source linked 1 email a week