NASA cFS Health & Safety App DoS Flaw
A NULL pointer dereference in NASA's Core Flight System Health & Safety application can crash the software via a routine telemetry request, causing denial of service.
CISA has published an advisory for a vulnerability in NASA's Core Flight System (cFS) Health & Safety (HS) Application, an open-source flight software framework used in spacecraft and other embedded control systems. The flaw, tracked as CVE-2026-15352, is a NULL pointer dereference (CWE-476) that causes the application to crash with a segmentation fault when processing a standard Housekeeping Telemetry request, resulting in a denial-of-service condition.
The vulnerability affects all versions of the HS Application prior to v7.0.1. NASA has released a patched version and recommends affected users update immediately. CISA notes no known public exploitation targeting this vulnerability has been reported. The advisory lists Transportation Systems as the relevant critical infrastructure sector, with deployments reported worldwide and the vendor headquartered in the United States. Standard ICS defense-in-depth recommendations, including network isolation and secure remote access, are advised as compensating controls.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free