S5 · 07/13
2026 ·
SharkNinja
| Company | SharkNinja |
| Category | consumer robotics |
| Type | cyber |
| Date | 07/13 2026 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S5 (fatality or catastrophic loss) |
| Scale | - |
| Confidence | medium |
| Verification | Yes - adversarially checked against the cited source |
| Source | Tom's Hardware / Cybernews / SC Media / CyberInsider |
A vulnerability in overly permissive AWS IoT device-certificate policies let a certificate stolen from one Shark robot vacuum run arbitrary MQTT commands on other customers' devices, exposing live camera feeds, home maps, and Wi-Fi credentials across an estimated 673,816+ devices; patched by SharkNinja on July 20, 2026.