CISA warned that PX4 Autopilot contains a critical vulnerability, CVE-2026-1579, that can let an unauthenticated attacker execute arbitrary shell commands through the MAVLink interface. The flaw affects PX4 Autopilot v1.16.0_SITL_latest_stable and stems from MAVLink not requiring cryptographic authentication by default, allowing attackers with interface access to send SERIAL_CONTROL messages that could alter flight paths, crash drones, intercept data, or lock out legitimate operators. CISA rated the issue CVSS 9.8 and mapped it to CWE-306: Missing Authentication for Critical Function.
The advisory said PX4 supports MAVLink 2.0 message signing as its authentication mechanism, and unsigned messages are rejected when signing is enabled. The vulnerability was reported by Dolev Aviv of Cyviation, and CISA said it had no evidence of public exploitation at publication. Because PX4 is used in drones and autonomous vehicles deployed worldwide, the agency said the exposure could affect Transportation Systems, Emergency Services, and the Defense Industrial Base, and urged organizations to reduce network exposure, isolate control systems behind firewalls, use secure remote access such as updated VPNs, assess operational risk before changes, train personnel against phishing, and apply vendor fixes when available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On March 31, 2026, CISA issued ICS advisory ICSA-26-090-02 for CVE-2026-1579, rating the flaw critical with a CVSS v3.1 score of 9.8. CISA said the issue could affect drone and autonomous vehicle deployments across transportation, emergency services, and defense sectors, and noted no known public exploitation at publication.
Dolev Aviv of Cyviation identified a vulnerability in PX4 Autopilot v1.16.0_SITL_latest_stable in which MAVLink does not require cryptographic authentication by default, allowing unauthenticated SERIAL_CONTROL messages that can lead to arbitrary shell command execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecisa.gov
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.