CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NASA Core Flight System (cFS) Health & Safety (HS) Application

criticalCVE-2026-18064CVE-2026-15352
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1 (CVE-2026-18064) CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18064 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. View CVE Details Affected Products NASA Core Flight System (cFS) Health & Safety (HS) Application Vendor: NASA Product Version: NASA Core Flight System (cFS) Health & Safety (HS) Application: <=v7.0.1 Product Status: known_affected Remediations Mitigation NASA reports that an official fix is currently under development and is expected to be included in a future software release. Mitigation As an interim mitigation, users can update their HS app from the HS repo (https://github.com/nasa/HS) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965 https://github.com/nasa/HS Relevant CWE: CWE-476 NULL Pointer Dereference Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Michael Holmquist of Hasp Labs reported this vulnerability to CISA Legal Notice and Terms o

CSIRTS triage

What
Successful exploitation could allow an attacker to cause a denial-of-service condition.
Who is affected
Deployments of the cFS Health & Safety Application version 7.0.1 and below.
Urgency
Remediation is critical due to the potential for denial of service in critical infrastructure.
Action
Update to a version above 7.0.1.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Core Flight System (cFS) Health & Safety (HS) Application

Get an email when a new Core Flight System (cFS) Health & Safety (HS) Application advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-30
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-18064coverage & exploitation statusNVD · CVE.org
CVE-2026-15352coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for NASA Core Flight

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories