Space Security News
  • Home
  • News

    Vast recruits Slingshot co-founder to lead defense satellite push

    July 27, 2026

    Commerce department launches voluntary certification for novel space missions

    July 27, 2026
    Sentinel satellite overlooking the Strait of Hormuz shipping lanes

    EU halts Copernicus imagery release near Iran war zone

    July 27, 2026
    Military GPS satellite with encrypted signal beams in orbit

    Air Force seizes control of troubled jam-proof GPS receiver project

    July 27, 2026
  • Features

    Classified Chinese satellite sweeps the geostationary belt for threats

    July 24, 2026

    Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

    July 24, 2026

    Software-defined radios open new attack surface for satellite networks

    July 22, 2026

    GPS jamming wave pushes UK toward self-reliant satellite security

    July 21, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: CISA warns of denial-of-service flaw in NASA flight software
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
Satellite Security

CISA warns of denial-of-service flaw in NASA flight software

CISA alerted operators that a null pointer dereference vulnerability in NASA's Core Flight System Health and Safety application could let attackers crash satellite and spacecraft flight software.

By
SSN Staff
Last updated: July 18, 2026
2 Min Read
Share

CISA issued an advisory on July 16 warning that a vulnerability in NASA’s Core Flight System (cFS) Health and Safety (HS) application could allow attackers to crash spacecraft flight software through a denial-of-service condition.

The flaw, tracked as CVE-2026-15352, is a NULL pointer dereference vulnerability with a CVSS v3 score of 7.5 (high severity). It affects the cFS Health and Safety application, a component widely used in NASA missions and adopted by other space agencies and commercial satellite developers.

The vulnerability causes the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request. An attacker with network access to the cFS stack could trigger the flaw repeatedly, disabling critical health monitoring functions on satellites and spacecraft.

The cFS framework is an open-source, reusable software platform developed by NASA’s Goddard Space Flight Center. It serves as the onboard flight software foundation for numerous NASA missions, including CubeSats, sounding rockets, and orbital spacecraft. The framework’s broad adoption outside NASA means the vulnerability could affect systems across the global space industry.

CISA recommended that operators apply available patches, restrict network access to cFS interfaces, and monitor for anomalous telemetry requests. The advisory was published under ICSA-26-197-03 as part of CISA’s ongoing effort to secure critical space infrastructure.

TAGGED:CISACore Flight SystemCVE-2026-15352denial of serviceflight softwareNASAsatellite software
SOURCES:CISA ICS Advisory ICSA-26-197-03

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Vast recruits Slingshot co-founder to lead defense satellite push

News
July 27, 2026

Commerce department launches voluntary certification for novel space missions

The Office of Space Commerce rolls out a voluntary certification system for novel space activities…

July 27, 2026
Sentinel satellite overlooking the Strait of Hormuz shipping lanes

EU halts Copernicus imagery release near Iran war zone

The EU imposed a 24-hour restriction on Sentinel satellite imagery of the Gulf of Oman…

July 27, 2026
Military GPS satellite with encrypted signal beams in orbit

Air Force seizes control of troubled jam-proof GPS receiver project

The Air Force absorbed the Pentagon's M-code GPS receiver program from the Space Force after…

July 27, 2026

YOU MAY ALSO LIKE

The Navy Wants Shipping Containers Full of Space Gear and It Wants Them Fast

The Defense Innovation Unit and the U.S.

Satellite Security
July 10, 2026

MITRE releases emb3d™ – a cybersecurity threat model for embedded devices

Satellites are embedded systems wrapped in radiation-hardened armor. When MITRE releases a threat model for embedded devices, it matters directly…

FeaturesSatellite Security
May 12, 2026

International air and space leaders push allied unity after NATO summit

International air and space leaders called for strengthened allied cooperation following the NATO summit's recognition of space as a warfighting…

Emerging Threats & TechNewsSatellite Security
July 18, 2026

Space Force designates third PAE tranche for electromagnetic warfare and cyber

The third tranche of Portfolio Alignment Effort designates electromagnetic warfare and cybersecurity as dedicated mission areas within the Space Force…

NewsSatellite SecurityThreat Actors & Incidents
July 18, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?