A researcher disclosed two root remote code execution chains in the Unitree G1 humanoid robot, one reachable over Bluetooth from nearby without any pairing. Tracked as CVE-2026-76639 and CVE-2026-76640, the Bluetooth chain abuses a gap in Unitree's cloud service, which handed over another robot's key material to any free account without checking ownership, then used a buffer overflow in the Wi-Fi provisioning code to run code as root on the robot's control computer. The researcher demonstrated that a compromised robot can spread the exploit to another within Bluetooth range, making it wormable. There is no confirmed fixed firmware for the on-robot flaws, though the cloud ownership check was tightened.
Palo Alto Networks confirmed Wednesday that attackers are exploiting a zero-day in its firewall login portal to run code as root on PA-Series and VM-Series firewalls. CVE-2026-0300 (CVSS 9.3) is a buffer overflow in the User-ID Authentication Portal (Captive Portal) that lets unauthenticated attackers send crafted packets and execute code without any login. Palo Alto Unit 42 attributed the activity to CL-STA-1132, a likely state-sponsored cluster that started probing on April 9 and achieved RCE a week later. Attackers deploy tunneling tools and enumerate Active Directory using the firewall's service account. First patches arrive May 13. Shadowserver counts 5,800+ exposed VM-Series firewalls.