# NASA cFS HS App NULL Pointer Flaw

Published: 2026-07-30 · Severity: low · Sectors: transportation
Canonical: https://vorant.io/reports/498926a2-a101-51d4-8b5e-b2714a52a5ca/nasa-cfs-hs-app-null-pointer-flaw

> An incomplete patch for a prior bug leaves NASA's Core Flight System HS application vulnerable to a NULL pointer dereference causing denial-of-service.

CISA published an advisory for a vulnerability in NASA's Core Flight System (cFS) Health & Safety (HS) Application, versions up to and including v7.0.1. The flaw, tracked as CVE-2026-18064, stems from an incomplete fix for a previously disclosed vulnerability (CVE-2026-15352) and leaves a NULL pointer dereference reachable under specific conditions.

An attacker able to trigger the affected command could crash the HS application, causing a denial-of-service condition and a processor reset. NASA is developing an official fix; in the interim, users are advised to update the HS app from the GitHub repository to the latest dev branch, which contains the patch. No known public exploitation of this vulnerability has been reported. The advisory notes worldwide deployment with the affected transportation systems sector, and standard ICS network hardening and segmentation practices are recommended as mitigations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18064

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/498926a2-a101-51d4-8b5e-b2714a52a5ca/nasa-cfs-hs-app-null-pointer-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
