Space Security News
  • Home
  • News

    Ukrainian cyber operation exposes Russia’s missile and space design institute

    September 10, 2026

    TrustPoint books 40 spacecraft to scale its GPS-free navigation net

    September 10, 2026

    Simulators let guardians rehearse satellite combat without risking the fleet

    September 10, 2026

    Pentagon nearly doubles national security launch buys as bill hits $76B

    September 9, 2026
  • Features

    First live-fly space exercise puts real satellites through orbital agility drills

    September 9, 2026

    US war game ends with two rival missile shields and no deal

    September 9, 2026

    Britain folds space defense and civil work into one £7.8B plan

    September 9, 2026

    Bundeswehr scouts jammers and spoofers to counter Russian satellites

    September 7, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: CISA warns of denial-of-service flaw in NASA flight software
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
Satellite Security

CISA warns of denial-of-service flaw in NASA flight software

CISA alerted operators that a null pointer dereference vulnerability in NASA's Core Flight System Health and Safety application could let attackers crash satellite and spacecraft flight software.

By
SSN Staff
Last updated: July 18, 2026
2 Min Read
Share

CISA issued an advisory on July 16 warning that a vulnerability in NASA’s Core Flight System (cFS) Health and Safety (HS) application could allow attackers to crash spacecraft flight software through a denial-of-service condition.

The flaw, tracked as CVE-2026-15352, is a NULL pointer dereference vulnerability with a CVSS v3 score of 7.5 (high severity). It affects the cFS Health and Safety application, a component widely used in NASA missions and adopted by other space agencies and commercial satellite developers.

The vulnerability causes the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request. An attacker with network access to the cFS stack could trigger the flaw repeatedly, disabling critical health monitoring functions on satellites and spacecraft.

The cFS framework is an open-source, reusable software platform developed by NASA’s Goddard Space Flight Center. It serves as the onboard flight software foundation for numerous NASA missions, including CubeSats, sounding rockets, and orbital spacecraft. The framework’s broad adoption outside NASA means the vulnerability could affect systems across the global space industry.

CISA recommended that operators apply available patches, restrict network access to cFS interfaces, and monitor for anomalous telemetry requests. The advisory was published under ICSA-26-197-03 as part of CISA’s ongoing effort to secure critical space infrastructure.

TAGGED:CISACore Flight SystemCVE-2026-15352denial of serviceflight softwareNASAsatellite software
SOURCES:CISA ICS Advisory ICSA-26-197-03

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Ukrainian cyber operation exposes Russia’s missile and space design institute

Emerging Threats & Tech
September 10, 2026

TrustPoint books 40 spacecraft to scale its GPS-free navigation net

TrustPoint has ordered 40 spacecraft from EnduroSat's U.S. arm to scale up a C-band navigation…

September 10, 2026

Simulators let guardians rehearse satellite combat without risking the fleet

The Space Force is buying portable simulators so satellite crews can rehearse jamming and interference…

September 10, 2026

Pentagon nearly doubles national security launch buys as bill hits $76B

A fresh Pentagon cost report shows the US military planning 337 rocket launches versus 151…

September 9, 2026

YOU MAY ALSO LIKE

Russian state hackers target routers used by satellite ground stations worldwide

Joint advisory warns Russian state hackers are targeting routers at satellite ground stations and space operations networks.

Ground Segment & OperationsPolicy, Law & GovernanceSatellite Security
July 14, 2026

OrbitWhisperer AI satellite cybersecurity framework presented to NATO

Embry-Riddle professor Rosa Szurgot developed the AI-driven OrbitWhisperer framework to detect and respond to cyber threats targeting satellite systems.

NewsSatellite SecurityThreat Actors & Incidents
July 17, 2026

Darknavy claims full control of the newest Starlink terminals

A Singapore-Shanghai research lab says hardware attacks gave it full administrative control of the newest Starlink user terminals.

Satellite Security
September 3, 2026

NorthStar reloads its orbital watch with 11 sensors on Kepler relays

NorthStar will fly 11 optical tracking sensors on Kepler relay satellites by 2028 after its first four spacecraft failed.

Satellite Security
August 27, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?