Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: root-rce (2 articles)Clear

Bluetooth flaw gives root on Unitree humanoid robots and can spread between them

A researcher disclosed two root remote code execution chains in the Unitree G1 humanoid robot, one reachable over Bluetooth from nearby without any pairing. Tracked as CVE-2026-76639 and CVE-2026-76640, the Bluetooth chain abuses a gap in Unitree's cloud service, which handed over another robot's key material to any free account without checking ownership, then used a buffer overflow in the Wi-Fi provisioning code to run code as root on the robot's control computer. The researcher demonstrated that a compromised robot can spread the exploit to another within Bluetooth range, making it wormable. There is no confirmed fixed firmware for the on-robot flaws, though the cloud ownership check was tightened.

Check
Owners of Unitree G1 robots should watch for firmware updates addressing these flaws, keep the robots off untrusted networks, and be aware that a nearby compromised unit could attack others over Bluetooth.
Affected
Unitree G1 humanoid robots (CVE-2026-76639, CVE-2026-76640); an attacker within Bluetooth range can chain a cloud key-recovery gap and a buffer overflow to gain root, and the exploit can spread robot to robot.
Fix
Isolate robots on segmented networks, limit physical and radio proximity by untrusted parties, apply firmware fixes when a confirmed release appears, and treat cyber-physical devices as full computers requiring patching.

Palo Alto Networks firewalls have a critical hole that lets attackers run code as root - hackers are already using it, no patch until May 13 (CVE-2026-0300)

Palo Alto Networks confirmed Wednesday that attackers are exploiting a zero-day in its firewall login portal to run code as root on PA-Series and VM-Series firewalls. CVE-2026-0300 (CVSS 9.3) is a buffer overflow in the User-ID Authentication Portal (Captive Portal) that lets unauthenticated attackers send crafted packets and execute code without any login. Palo Alto Unit 42 attributed the activity to CL-STA-1132, a likely state-sponsored cluster that started probing on April 9 and achieved RCE a week later. Attackers deploy tunneling tools and enumerate Active Directory using the firewall's service account. First patches arrive May 13. Shadowserver counts 5,800+ exposed VM-Series firewalls.

Check
Inventory Palo Alto PA-Series and VM-Series firewalls. Check whether the User-ID Authentication Portal is enabled and reachable from untrusted IPs. Hunt nginx crash logs for evidence of clearing since April 9.
Affected
PA-Series and VM-Series firewalls running PAN-OS with the User-ID Authentication Portal exposed to public internet or untrusted IPs. CVE-2026-0300, CVSS 9.3 (8.7 if portal restricted to internal IPs). Prisma Access, Cloud NGFW, and Panorama are NOT affected. Shadowserver tracks 5,800+ exposed VM-Series instances; thousands more likely sit behind load balancers.
Fix
Restrict the User-ID Authentication Portal to trusted internal networks - this is the primary mitigation until patches arrive. Disable the portal entirely if not strictly required. Block ports 6081 and 6082 from untrusted IPs. Stage May 13 patches: 12.1.4-h5, 11.2.7-h13, 11.1.4-h33, 10.2.10-h36. Treat any compromised firewall as a domain-wide breach starting point - rotate firewall service account credentials.