RobotRisk › SharkNinja › 13 Jul 2026
Shark robot vacuum flaw allows remote code execution via stolen certificate
S5 · 13 Jul 2026 · SharkNinja
Record
| Company | SharkNinja |
| Industry | Consumer robotics |
| Type(s) | cyber |
| Date | 13 Jul 2026 (day precision) |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | (fatality or catastrophic loss) |
| Scale | not documented |
| Confidence | medium |
| Verified flag | Yes - independently re-checked against the cited source |
Summary
A vulnerability in overly permissive AWS IoT device-certificate policies let a certificate stolen from one Shark robot vacuum run arbitrary MQTT commands on other customers' devices, exposing live camera feeds, home maps, and Wi-Fi credentials across an estimated 673,816+ devices; patched by SharkNinja on July 20, 2026.
Primary source
Tom's Hardware / Cybernews / SC Media / CyberInsider
Publisher: Tom's Hardware / Cybernews / SC Media / CyberInsider · Retrieved: 2026-09-16
Supporting source rows (1)
| Date | Supporting source row | Publisher | Link |
|---|---|---|---|
| 13 Jul 2026 | Shark robot vacuum flaw allows remote code execution via stolen certificate | Tom's Hardware / Cybernews / SC Media / CyberInsider | Tom's Hardware / Cyberne |
Consumer robotics context
cyber context
SharkNinja industry position
Related incidents
Other SharkNinja entries
- None on file.
Report a correction
Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs