π΅οΈ RESEARCH & DEEP DIVES
- Unitree G1 EDU Firmware Exposes Unauthenticated Bluetooth Root RCE
CVE-2026-76639
Unitree G1 EDU robots are vulnerable to unauthenticated remote code execution.- Unitree G1 EDU humanoid robots are affected.
- Firmware versions through 1.5.2 are vulnerable to CVE-2026-76639.
- An attacker within Bluetooth range can execute commands without authentication.
- The vulnerability provides root-level access through the robotβs Bluetooth interface.
π Source: boschko.ca Β· π Coverage: thehackerwire.com Β· π via thehackerwire.com (discovered), r/netsec
π CVEs & KEV
-
CVE-2026-74820 β CVSS 10.0 β Unauthenticated SQL Injection via Dynamic Schema ORDER BY ClauseServiceNow ha...
-
CVE-2026-18886 β CVSS 10.0 β Unauthenticated Privilege Escalation via System Configuration Image Upload Pr...
-
CVE-2026-18885 β CVSS 10.0 β Unauthenticated Remote Code Execution in GraphQL Composite Data APIServiceNow...
-
CVE-2026-53579 β CVSS 9.3 β Trilium: Note Import to RCE via Book NoteTrilium is an open-source hierarchic...
-
CVE-2026-53578 β CVSS 9.3 β Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtmlTrilium is...
-
CVE-2026-81934 β CVSS 9.2 β Redis TLS pending-data list use-after-freeRedis contains a use-after-free vul...
-
CVE-2026-81730 β CVSS 8.8 β Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Fi...
-
CVE-2026-10036 β CVSS 8.7 β SpeechBrain before 1.1.1 Arbitrary Code Execution via CKPT.yaml ParsingSpeechBrain...
-
CVE-2026-6876 β CVSS 8.7 β Sandbox Escape in Now PlatformServiceNow has remediated a sandbox escape secu...
-
CVE-2026-76639 β CVSS 8.7 β Unitree G1 EDU Firmware RCE (CVE-2026-76639)
-
CVE-2026-81728 β CVSS 8.6 β Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update KeysD...
-
CVE-2026-53580 β CVSS 8.1 β Trilium arbitrary file read and denial of service via file:// URLs in the aut...
-
CVE-2026-77438 β CVSS 7.5 β Trilium unauthenticated share-search discloses password-protected and hidden ...
-
CVE-2026-81729 β CVSS 7.1 β Dolibarr before 23.0.4 Incorrect Authorization on REST API Document DeletionD...