Skip to content
Threat Feed

Vendor

NASA

5 briefs RSS
high advisory

Integer Underflow Vulnerability in NASA cFS cFE Software Bus

An integer underflow vulnerability in the CFE_SB_GetUserDataLength function of the NASA cFS cFE Software Bus (up to version 7.0.1) allows remote attackers to trigger memory corruption via manipulated message size arguments.

cFS +1
1c
high advisory

Remote Buffer Overflow in NASA Trick JSONVariableServer

CVE-2026-82478 is a stack-based buffer overflow in the NASA Trick simulation environment (version 19.6.0) that enables remote attackers to trigger memory corruption via the TCP Socket Handler.

Trick cve vulnerability remote-code-execution nasa-trick
1t 1c
critical advisory

Unauthenticated API Access in AMMOS Instrument Toolkit DSN Interface

The AMMOS Instrument Toolkit (AIT) DSN Interface prior to version 2.2.2 contains a missing authentication vulnerability in the Space Link Extension interface manager, allowing unauthenticated attackers to invoke sensitive API routes.

AMMOS Instrument Toolkit api-security authentication-bypass cve-2026-60113
1t 1c
critical advisory

Authentication Bypass in AMMOS Instrument Toolkit GUI

The AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.

AMMOS Instrument Toolkit authentication-bypass cve-2026-60112 critical-infrastructure
1t 1c
medium threat

NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability

A high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.

exploited NASA Core Flight System cve vulnerability denial-of-service ics space transportation
1t