Space Security News
  • Home
  • News

    Vast recruits Slingshot co-founder to lead defense satellite push

    July 27, 2026

    Commerce department launches voluntary certification for novel space missions

    July 27, 2026
    Sentinel satellite overlooking the Strait of Hormuz shipping lanes

    EU halts Copernicus imagery release near Iran war zone

    July 27, 2026
    Military GPS satellite with encrypted signal beams in orbit

    Air Force seizes control of troubled jam-proof GPS receiver project

    July 27, 2026
  • Features

    Classified Chinese satellite sweeps the geostationary belt for threats

    July 24, 2026

    Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

    July 24, 2026

    Software-defined radios open new attack surface for satellite networks

    July 22, 2026

    GPS jamming wave pushes UK toward self-reliant satellite security

    July 21, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: CISA warns of denial-of-service flaw in NASA flight software
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
Satellite Security

CISA warns of denial-of-service flaw in NASA flight software

CISA alerted operators that a null pointer dereference vulnerability in NASA's Core Flight System Health and Safety application could let attackers crash satellite and spacecraft flight software.

By
SSN Staff
Last updated: July 18, 2026
2 Min Read
Share

CISA issued an advisory on July 16 warning that a vulnerability in NASA’s Core Flight System (cFS) Health and Safety (HS) application could allow attackers to crash spacecraft flight software through a denial-of-service condition.

The flaw, tracked as CVE-2026-15352, is a NULL pointer dereference vulnerability with a CVSS v3 score of 7.5 (high severity). It affects the cFS Health and Safety application, a component widely used in NASA missions and adopted by other space agencies and commercial satellite developers.

The vulnerability causes the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request. An attacker with network access to the cFS stack could trigger the flaw repeatedly, disabling critical health monitoring functions on satellites and spacecraft.

The cFS framework is an open-source, reusable software platform developed by NASA’s Goddard Space Flight Center. It serves as the onboard flight software foundation for numerous NASA missions, including CubeSats, sounding rockets, and orbital spacecraft. The framework’s broad adoption outside NASA means the vulnerability could affect systems across the global space industry.

CISA recommended that operators apply available patches, restrict network access to cFS interfaces, and monitor for anomalous telemetry requests. The advisory was published under ICSA-26-197-03 as part of CISA’s ongoing effort to secure critical space infrastructure.

TAGGED:CISACore Flight SystemCVE-2026-15352denial of serviceflight softwareNASAsatellite software
SOURCES:CISA ICS Advisory ICSA-26-197-03

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Vast recruits Slingshot co-founder to lead defense satellite push

News
July 27, 2026

Commerce department launches voluntary certification for novel space missions

The Office of Space Commerce rolls out a voluntary certification system for novel space activities…

July 27, 2026
Sentinel satellite overlooking the Strait of Hormuz shipping lanes

EU halts Copernicus imagery release near Iran war zone

The EU imposed a 24-hour restriction on Sentinel satellite imagery of the Gulf of Oman…

July 27, 2026
Military GPS satellite with encrypted signal beams in orbit

Air Force seizes control of troubled jam-proof GPS receiver project

The Air Force absorbed the Pentagon's M-code GPS receiver program from the Space Force after…

July 27, 2026

YOU MAY ALSO LIKE

A continuing resolution freezes more than money — it freezes vulnerabilities

Congress is fumbling the bag on space defense, and the clock is ticking.

NewsSatellite Security
May 14, 2026

Gen. Guetlein challenges Golden Dome’s 1.2 trillion dollar price tag as Army battles the Spectrum Blackout

Space Force Gen.

Satellite SecuritySpotlight
May 19, 2026

L3Harris and Sierra Space to build 36 missile-tracking satellites

The new satellites will expand the US missile-tracking network in low Earth orbit, adding capacity for hypersonic and ballistic missile…

Satellite Security
July 17, 2026

Cybersecurity in space is hard; in cislunar space, it’s really hard

The Moon is three seconds away. That’s the round-trip lag for a radio signal between Earth and lunar orbit. For…

FeaturesSatellite Security
May 12, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?