CISA issued an advisory on July 16 warning that a vulnerability in NASA’s Core Flight System (cFS) Health and Safety (HS) application could allow attackers to crash spacecraft flight software through a denial-of-service condition.
The flaw, tracked as CVE-2026-15352, is a NULL pointer dereference vulnerability with a CVSS v3 score of 7.5 (high severity). It affects the cFS Health and Safety application, a component widely used in NASA missions and adopted by other space agencies and commercial satellite developers.
The vulnerability causes the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request. An attacker with network access to the cFS stack could trigger the flaw repeatedly, disabling critical health monitoring functions on satellites and spacecraft.
The cFS framework is an open-source, reusable software platform developed by NASA’s Goddard Space Flight Center. It serves as the onboard flight software foundation for numerous NASA missions, including CubeSats, sounding rockets, and orbital spacecraft. The framework’s broad adoption outside NASA means the vulnerability could affect systems across the global space industry.
CISA recommended that operators apply available patches, restrict network access to cFS interfaces, and monitor for anomalous telemetry requests. The advisory was published under ICSA-26-197-03 as part of CISA’s ongoing effort to secure critical space infrastructure.