Critical PX4 Autopilot Vulnerability Let Attackers Gain Control of Drones
ID: ee93987a-1cea-5bb2-b998-986d277cf62e
STIX ID: report--ee93987a-1cea-5bb2-b998-986d277cf62e
Feed Name: GBHackers
Threat Score
CISA has issued a high-priority advisory for CVE-2026-1579, a critical (CVSS 9.8) "Missing Authentication for Critical Function" flaw in PX4 Autopilot v1.16.0_SITL_latest_stable that allows unauthenticated access to MAVLink and remote execution of arbitrary shell commands, potentially enabling full takeover of drones used across transportation, emergency services, and defense; operators are urged to restrict MAVLink access and apply updates when available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
