Monday, October 5, 2026 Sign inSubscribe to The Brief →
Humanoid Threats

Security for the age of physical AI

Analysis

State of Humanoid Robot Security 2026: Vulnerabilities, Trends and Regulation

The State of Humanoid Robot Security 2026: every public robot CVE, the attack paths behind them, AI-driven discovery, the FCC ban and what to do next.

Humanoid robot security in 2026, in one sentence: the flaws are basic, they give full control, and regulators have started treating robots as national-security devices. This report pulls together every public vulnerability and research finding in our Humanoid Robot Vulnerability Tracker, plus the year's biggest policy move, into the numbers and trends that matter for teams building, buying or running robots.

Data as of October 4, 2026. Updated quarterly.

Key findings

  • 6 CVEs affecting humanoid, legged and collaborative robots are in our tracker, and 4 of them affect humanoids (all on Unitree platforms: G1, H1).
  • 5 of the 6 CVEs give an attacker full control: root code execution, an OS command injection, or a remote-control backdoor.
  • Wireless setup is the most common way in. 3 of the 6 CVEs sit in Bluetooth Low Energy (BLE) setup and pairing.
  • AI is speeding up discovery. One 2026 research project found 38 vulnerabilities in about 7 hours across three consumer robots, 30 of them Critical or High, with an AI-assisted workflow.
  • Patch status is often unclear. For the two newest humanoid CVEs (August 2026), no fixed firmware had been publicly confirmed weeks after disclosure.
  • Regulation arrived. On July 28, 2026 the US FCC added foreign-produced advanced robotic devices, including humanoids, to its Covered List, citing security risks.

The numbers

Metric (public records, Oct 4, 2026) Value
CVEs tracked (humanoid, legged and collaborative robots) 6
CVEs affecting humanoid robots 4
CVEs giving full control (root, OS command injection or backdoor) 5
CVEs entering through Bluetooth / wireless setup 3
CVEs entering through an AI assistant service 1
Highest CVSS score 9.8 Critical (CVE-2026-8153, Universal Robots PolyScope 5)
Vulnerabilities found in one AI-assisted consumer-robot study 38 (30 Critical or High)

Small numbers, big implications: humanoids are early in deployment, and public research has concentrated on the most widely sold platforms. Expect these counts to grow quickly as more models ship and more researchers look.

The most repeated pattern in 2025-2026 is unauthenticated or poorly protected Bluetooth setup. The "UniPwn" flaw (CVE-2025-35027) allowed command injection while configuring Wi-Fi over BLE on Unitree G1, H1, Go2 and B2 robots, and a companion issue (CVE-2025-60250) used a hardcoded encryption key. In August 2026, CVE-2026-76640 again gave root access over BLE on the Unitree G1 EDU, with no pairing required. Details are in our Unitree G1 explainer.

Our analysis: setup flows are designed for convenience in the lab, then shipped unchanged into products that end up in offices and public spaces.

Trend 2: The robot's AI assistant is a new attack surface

CVE-2026-76639 reached root code execution through the G1's AI chatbot service. As humanoids increasingly take spoken or written instructions through language models, the path from "talk to the robot" to "run code on the robot" becomes a security boundary. Our explainer on physical AI covers why this matters.

Trend 3: AI is accelerating vulnerability discovery

In March 2026, researchers from Alias Robotics and IOActive used an AI-assisted workflow to find 38 vulnerabilities in a robot lawnmower, a powered exoskeleton and a window-cleaning robot in about seven hours. Our analysis: if consumer and service robots can be audited this fast, humanoid platforms should expect a steady stream of findings, from defenders and attackers alike.

Trend 4: Patch transparency lags behind disclosure

For several tracked issues, public records list affected versions but not a clearly documented fix, and for the August 2026 G1 CVEs no fixed firmware had been publicly confirmed weeks later. Buyers should ask vendors directly which firmware version fixes each CVE, and get it in writing.

Trend 5: Robots are now a national-security question

On July 28, 2026 the FCC added foreign-produced "advanced robotic devices" (humanoids, quadrupeds, warehouse robots, delivery and household robots) to its Covered List, blocking new FCC equipment authorizations for those models. Already-authorized models can still be sold and used, and a waiver lets vendors keep shipping security patches until at least January 1, 2029. Read our FCC robot ban explainer for what it does and doesn't change.

What to do in 2027

  1. Inventory every robot with its model and firmware version, and track CVEs for each.
  2. Turn off Bluetooth after setup and never leave robots in pairing mode in shared spaces.
  3. Put robots on their own network segment with no inbound internet access.
  4. Restrict who can talk to the robot's AI assistant, and log what it is asked to do.
  5. Make sure emergency stops are hardwired and independent of software.

The full list is in our free Humanoid Robot Security Checklist, and vendors who can help are in the Humanoid Robot Security Directory.

Methodology

This report counts publicly disclosed vulnerabilities (CVE records and published research) affecting humanoid robots and closely related legged, collaborative and consumer robots, as listed in our vulnerability tracker on October 4, 2026. We count each CVE once even when it affects several models. Limitations: the sample is small, public research is concentrated on a few popular platforms, and undisclosed vulnerabilities are by definition not counted. Every figure links back to a primary source in the tracker. See our editorial standards.

Cite this report

You're welcome to quote and chart these findings with a link. Suggested citation: Humanoid Threats, "State of Humanoid Robot Security 2026", humanoidthreats.com, October 2026. For questions or corrections, email info@humanoidthreats.com.

Sources


Get the weekly Humanoid Threats Brief → Subscribe

The Humanoid Threats Brief

The weekly briefing on humanoid robot security.

New vulnerabilities, incidents, standards and defenses, with why each one matters. Built for security teams, robotics engineers and the people buying humanoids.

  • Every claim sourced. We link the CVE, the paper or the regulator, not rumors.
  • 5-minute read. One email a week, every Thursday.
  • Free. No spam, unsubscribe in one click.

Check your inbox to confirm your subscription.

Something went wrong. Please try again.

Read a recent storyUnitree G1 Vulnerabilities Explained: CVE-2026-76639 and CVE-2026-76640 →
100% primary-source linked 1 email a week