CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18064

criticalCVSS 7.5covered by 2 sourcesfirst seen 2026-07-30
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1 (CVE-2026-18064) CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18064 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. View CVE Details Affected Products NASA Core Flight System (cFS) Health & Safety (HS) Application Vendor: NASA Product Version: NASA Core Flight System (cFS) Health & Safety (HS) Application: <=v7.0.1 Product Status: known_affected Remediations Mitigation NASA reports that an official fix is currently under development and is expected to be included in a future software release. Mitigation As an interim mitigation, users can update their HS app from the HS repo (https://github.com/nasa/HS) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965 https://github.com/nasa/HS Relevant CWE: CWE-476 NULL Pointer Dereference Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Michael Holmquist of Hasp Labs reported this vulnerability to CISA Legal Notice and Terms o

CSIRTS triage

What
Successful exploitation could allow an attacker to cause a denial-of-service condition.
Who is affected
Deployments of the cFS Health & Safety Application version 7.0.1 and below.
Urgency
Remediation is critical due to the potential for denial of service in critical infrastructure.
Action
Update to a version above 7.0.1.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-18064

Get an email if CVE-2026-18064 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-18064

CVE.org record

Embed the live status

CVE-2026-18064 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18064 status](https://www.csirts.com/badge/CVE-2026-18064)](https://www.csirts.com/cve/CVE-2026-18064)