NASA vulnerabilities
3 CVEs tracked
In our reporting, NASA appears primarily in the context of spacecraft flight software, specifically vulnerabilities in the core Flight System (cFS) and HyperCP tool. Key incidents involve an incomplete fix in the cFS Health and Safety (HS) application (CVE-2026-18064) and an access control weakness in the Executive Services component (CVE-2026-67979), along with an OS command injection in HyperCP (CVE-2026-72579). Additionally, a flaw in the AIT-GUI ground control software exposes it to unauthenticated commands. Defenders should urgently patch NASA cFS versions, implement network-level monitoring for suspicious traffic targeting tools like HyperCP, and enforce strong authentication on ground control systems.
Azərbaycanca: Hesabatlarımızda NASA əsasən kosmik uçuşlar üçün proqram təminatı kontekstində, xüsusilə core Flight System (cFS) və HyperCP alətlərindəki təhlükəsizlik boşluqları ilə bağlı görünür. Əsas hadisələr cFS-in 'Health and Safety' (HS) tətbiqində tamamlanmamış düzəliş (CVE-2026-18064) və 'Executive Services' komponentindəki icazə nəzarəti zəifliyi (CVE-2026-67979) ilə bağlıdır, həmçinin HyperCP-də OS əmr inyeksiyası (CVE-2026-72579) müəyyən edilib. Ayrıca, yerüstü idarəetmə proqramı AIT-GUI-də autentifikasiya olunmamış əmrlərin icrasına imkan verən boşluq qeydə alınıb. Müdafiəçilər xüsusilə NASA cFS versiyalarını təcili yeniləməli, şəbəkə səviyyəsində HyperCP kimi alətlərə şübhəli trafik monitorinqi tətbiq etməli və yerüstü sistemlərdə güclü autentifikasiya mexanizmlərini təmin etməlidirlər.
This vendor's CVEs3
This hub is built from skopnix's own reporting on NASA: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.