CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NASA Core Flight System (cFS) Health & Safety (HS) Application

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3569

As cited

Copy frozen at (site build).

vulnerabilities

NASA Core Flight System (cFS) Health & Safety (HS) Application

NASA's Core Flight System (cFS) Health and Safety application versions through 7.0.1 contain a NULL pointer dereference vulnerability (CVE-2026-18064) that an attacker can exploit to cause denial-of-service conditions and processor resets. The flaw is an incomplete fix for a prior vulnerability. NASA is developing an official patch, with interim mitigation available through the latest development branch on GitHub.

Why it matters: Organizations deploying NASA cFS HS application in transportation and critical infrastructure systems worldwide should update to the dev branch immediately or implement network isolation measures to prevent remote exploitation that could disrupt essential operations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NASA Core Flight System (cFS) Health & Safety (HS) Application

NASA's Core Flight System (cFS) Health and Safety application versions through 7.0.1 contain a NULL pointer dereference vulnerability (CVE-2026-18064) that an attacker can exploit to cause denial-of-service conditions and processor resets. The flaw is an incomplete fix for a prior vulnerability. NASA is developing an official patch, with interim mitigation available through the latest development branch on GitHub.

Why it matters: Organizations deploying NASA cFS HS application in transportation and critical infrastructure systems worldwide should update to the dev branch immediately or implement network isolation measures to prevent remote exploitation that could disrupt essential operations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary