CVE-2026-1579Disclosure(px4 / autopilot)

HIGHCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch px4 autopilot systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink interface. PX4 provides MAVLink 2.0 message signing as the cryptographic authentication mechanism for all MAVLink communication. When signing is enabled, unsigned messages are rejected at the protocol level.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • autopilot

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 16 signals
  • Disclosure: 11 classified signals
  • Peaked 4d ago at 7 mentions (2026-04-01); latest day: 1
  • 17 total mentions across 6 days

Affected systems

Vendors
Products
autopilot

1 version affected across 1 product

Deep dive

Activity timeline17 mentions / 6d
02457Mentions · 2026-03-31: 4Mentions · 2026-04-01: 7Mentions · 2026-04-02: 3Mentions · 2026-04-07: 1Mentions · 2026-04-09: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-03-31: 1Exploit Tool / Code · 2026-03-31: 1Active Exploitation · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 2Patch / Workaround · 2026-04-07: 1Technical Details · 2026-03-31: 4Technical Details · 2026-04-01: 7Technical Details · 2026-04-02: 2Technical Details · 2026-04-07: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-15: 103-3104-0104-0204-0704-0904-15
Signal classification5 categories
Disclosure
1164.7%
Patch
317.6%
Exploit
15.9%
Active Exploitation
15.9%
General
15.9%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-314
Disclosure2Exploit1Patch1
2026-04-017
Active Exploitation1Disclosure5Patch1
2026-04-023
Disclosure2Patch1
2026-04-071
Disclosure1
2026-04-091
Disclosure1
2026-04-151
General1
Full discourse17 posts
  • kokumօtօ@__kokumoto
    Disclosure

    【ドローンの脆弱性】ドローン間コミュニケーションの業界標準規格であるPX4 Autopilotに重大(Critical)な脆弱性。CVE-2026-1579はCVSSスコア9.8で、通信プロトコルMAVLinkでは既定で認証が無いというもの。任意コマンド実行可能。 https://securityonline.info/px4-autopilot-mavlink-vulnerability-cve-2026-1579/

    Post summary

    A critical vulnerability (CVE‑2026‑1579) in PX4 Autopilot’s MAVLink protocol has been disclosed, allowing unauthenticated remote command execution with a CVSS score of 9.8.

    030821.1K
    7.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ドローン制御ソフトウェア PX4 Autopilot の脆弱性 CVE-2026-1579:乗っ取りの恐れを CISA が警告 https://iototsecnews.jp/2026/04/02/critical-px4-autopilot-vulnerability-let-attackers-gain-control-of-drones/ 重要インフラや防衛産業で広く利用されている、ドローン用オープンソース飛行制御ソフトウェア PX4 Autopilot に発見された、きわめて深刻な脆弱性 CVE-2026-1579 (CVSS 9.8) について解説する記事です。この問題の原因は、ドローンと地上制御ステーションを結ぶ通信プロトコル MAVLink において、重要な命令を実行する際の認証プロセスが欠落していたことにあります。ウクライナやイランの戦争で多用されているドローンであるため、とても気になる脆弱性です。 #Government #PX4Autopilot #Vulnerability

    Post summary

    The article reports on CVE-2026-1579 in PX4 Autopilot, offering technical details of the flaw and its severity, but does not provide any PoC, exploit code, active exploitation evidence, or patch information.

    01000153
    483 followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 ثغرة وصول غير مصادق عليه (Unauthenticated Shell Access) في نظام PX4 Autopilot بتقييم CVSS 9.8 🛡️ الفئة: ثغرة 📝 الملخص: صدر تحذير أمني حرج بخصوص نظام القيادة الذاتية PX4 Autopilot. تم رصد ثغرة خطيرة، CVE-2026-1579، تسمح بالوصول غير المصادق عليه (Unauthenticated Shell Access) إلى الأنظمة المتأثرة. تحمل هذه الثغرة تقييم CVSS يبلغ 9.8، مما يشير إلى قدرتها على التسبب بسيناريو كارثي للطائرات المسيرة غير المحصنة. تُمكن الثغرة المهاجمين من السيطرة الكاملة على الطائرات المتأثرة. يُنصح بشدة بتطبيق التحديثات الأمنية فوراً لتقليل مخاطر الاستغلال. 🗓️ تاريخ النشر: 01/04/2026 🔗 للمزيد: https://securityonline.info/px4-autopilot-mavlink-vulnerability-cve-2026-1579/

    Post summary

    The advisory highlights a critical CVE‑2026‑1579 vulnerability in PX4 Autopilot, enabling unauthenticated shell access with a CVSS score of 9.8, and stresses the immediate implementation of available security updates.

    00010117
    8.9K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Critical PX4 Autopilot Vulnerability Allowing Drone Takeover (CVE-2026-1579) 📅 **Timeline:** Disclosure: 2026-03-31; Patch: Not Available 🆔 **CVE-2026-1579** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 22.05% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** PX4 Autopilot v1.16.0_SITL_latest_stable (MAVLink 2.0 message signing not enabled) 🫨 **Attack Vectors:** - Network access to MAVLink interface - Unauthenticated MAVLink messages (e.g., SERIAL_CONTROL) providing interactive shell access - Access via unsecured radios/serial-to-network bridges or exposed telemetry links 📝 **Summary:** CVE-2026-1579 is a missing-authentication flaw in PX4's MAVLink handling that allows unauthenticated attackers with access to the MAVLink interface to send messages (e.g., SERIAL_CONTROL) that execute shell commands, enabling full remote drone takeover. Consequences include loss of control/telemetry, physical damage, and data exfiltration across transportation, emergency services, defense, and other PX4 deployments. 📈 **Impact Scope:** Full vehicle takeover (loss of control/telemetry), potential physical damage, data exfiltration or espionage; affects critical sectors including Transportation Systems, Emergency Services, Defense Industrial Base. 🛡️ **Recommended Actions:** - Enable MAVLink 2.0 message signing on all non-USB links immediately - Restrict MAVLink interface access to trusted networks and hosts - Place flight-control networks behind firewalls and isolate from business networks - Use VPNs for remote access and disable/restrict SERIAL_CONTROL where not required - Monitor PX4 and CISA advisories and apply vendor patches when published - Implement network segmentation, logging and IDS/alerting for MAVLink traffic 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-090-02 - https://docs.px4.io/main/en/mavlink/message_signing 🏷 **Tags:** #Cybersecurity #PX4 #DroneSecurity

    Post summary

    The post announces CVE-2026-1579, a critical missing‑authentication flaw in PX4 that allows remote takeover via MAVLink; while no PoC or exploit code is disclosed, actionable mitigations and a link to vendor guidance are provided.

    0001054
    277 followersView on X
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-1579: MAVLink Protocol Unauthenticated Shell Access https://labs.cosmicbytez.ca/security/cve-2026-1579 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces a new vulnerability (CVE-2026-1579) in the MAVLink protocol that allows unauthenticated shell access; technical details are present, but no PoC, active exploitation, or patch information is disclosed.

    0001053
    1 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    PX4 Autopilot faces a critical 9.8 CVSS flaw (CVE-2026-1579). Unsigned MAVLink messages allow remote shell access. Enable message signing now to secure your fleet. #PX4Autopilot #DroneSecurity #MAVLink #CyberSecurity #InfoSec #UAV #Robotics #CVE https://securityonline.info/px4-autopilot-mavlink-vulnerability-cve-2026-1579/ https://t.co/zYsCWNuqk4

    Post summary

    PX4 Autopilot has a critical remote shell vulnerability (CVE‑2026‑1579); users are urged to enable MAVLink message signing immediately to mitigate the risk.

    00010258
    11.0K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2026-1579: PX4 Autopilot Remote Command Execution — Detection and Hardening… "CISA has released ICS Advisory ICSA-26-090-02 detailing a critical vulnerability…" 🔗 https://securityarsenal.com/blog/cve-2026-1579-px4-autopilot-remote-command-execution-detection-and-hardening-guide #CyberSecurity #ThreatIntel #soc #threatintel #managedsoc

    Post summary

    The post references CVE-2026-1579, noting its remote command execution flaw in PX4 Autopilot and links to a detection/hardening guide, but does not provide explicit PoC, exploit code, or evidence of active exploitation.

    0000026
    10 followersView on X
  • ZeitTrender@ZeitTrender
    Disclosure

    🚨Critical PX4 Autopilot Flaw (CVE-2026-1579, CVSS 9.8): Attackers can hijack drones via unauthenticated MAVLink commands and run arbitrary shell code, no password needed. Affects v1.16.0_SITL_latest_stable; impacts drones in defense, emergency, and transport sectors. CISA advisory issued. Restrict MAVLink access immediately and watch for patches. Discovered by Dolev Aviv (Cyviation). #CISA #CyberSecurity #PX4 Full details: https://gbhackers.com/critical-px4-autopilot-vulnerability/

    Post summary

    The tweet discloses a critical PX4 autopilot flaw (CVE‑2026‑1579) with a high CVSS score, details its RCE nature via unauthenticated MAVLink commands, and recommends restricting access while awaiting a vendor patch.

    0000080
    63 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: CISA issues high-priority alert on CVE-2026-1579 in PX4 Autopilot, critical flaw allows full remote takeover of drones used in vital infrastructure operations. https://threatcluster.io/cluster/critical-px4-autopilot-vulnerability-allows-drone-control-ta-b69fe3ed

    Post summary

    CISA has issued a high‑priority alert for CVE‑2026‑1579 in PX4 Autopilot, noting a critical flaw that could enable full remote takeover of drones. No exploitation, patch, or PoC details are supplied.

    0000047
    128 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Ghost in the Drone: Unauthenticated Shell Access in PX4 Autopilot’s 9.8 CVSS Nightmare https://securityonline.info/px4-autopilot-mavlink-vulnerability-cve-2026-1579/

    Post summary

    The headline announces a critical unauthenticated shell access flaw in PX4 Autopilot, but offers no evidence of exploitation, patch, or PoC.

    0000051
    241 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting unauthenticated MAVLink protocol (CVE-2026-1579) to execute arbitrary shell commands on PX4 Autopilot systems. Post-compromise lateral movement through connected drone infrastructure exposes broader network risks. Runtime segmentation helps contain such breach chains. #ZeroDay #IoTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/px4-autopilot-2026-mavlink-vulnerability

    Post summary

    Attackers are actively exploiting CVE-2026-1579 to run arbitrary shell commands on PX4 Autopilot drones, facilitating lateral movement through connected infrastructure; runtime segmentation is suggested as a containment measure.

    0000049
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1579 The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including… https://www.cve.org/CVERecord?id=CVE-2026-1579

    Post summary

    The CVE details a lack of default cryptographic authentication in MAVLink 2.0, allowing unsignable messages, but no proof of concept, exploit, or patch is provided.

    00000138
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1579 - Critical The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, whi... https://www.thehackerwire.com/vulnerability/CVE-2026-1579/ https://t.co/MU69I3Y7Vt

    Post summary

    The tweet announces the critical CVE-2026-1579 affecting the MAVLink protocol, noting the lack of default cryptographic authentication and linking to a detailed write‑up.

    0000038
    163 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1579 - PX4 Autopilot Missing authentication for critical function Intel Report: https://ift.tt/WiY4aMF

    Post summary

    An alert references CVE‑2026‑1579, a missing authentication flaw in PX4 Autopilot, citing an Intel report but providing no proof‑of‑concept, exploit, or mitigation details.

    0000040
    281 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1579: CRITICAL] MAVLink communication lacks default encryption authentication, making it vulnerable. Enabling MAVLink 2.0 message signing in PX4 provides cryptographic protection.#cve,CVE-2026-1579,#cybersecurity https://cvefind.com/CVE-2026-1579

    Post summary

    The tweet highlights a critical vulnerability in MAVLink’s lack of encryption authentication and recommends enabling MAVLink 2.0 message signing in PX4 to mitigate the risk.

    0000049
    617 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-1579: PX4 Autopilot Missing authenticat... Unauthenticated MAVLink SERIAL_CONTROL commands = instant root shell on drones - because who needs auth when you're flyi... https://zerodaysignal.com/vulnerability/CVE-2026-1579 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑1579, a misconfiguration in PX4 Autopilot that permits unauthenticated MAVLink SERIAL_CONTROL commands to obtain a root shell on drones.

    0000063
    194 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 PX4 + unauthenticated MAVLink = “just trust me bro” security. If signing isn’t enabled, attackers can go from packets to shell—great. OT/IoT needs threat modeling yesterday. https://windowsforum.com/threads/cve-2026-1579-critical-px4-mavlink-unsigned-commands-enable-shell-access.408853/ #CisaAdvisory #Px4Autopilot #MavlinkSecurity #UavCyberSecurity

    Post summary

    The post highlights an unauthenticated command execution flaw in PX4's MAVLink interface that can lead to shell access, but it does not provide a PoC, exploit code, or patch information.

    0000028
    1.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppx4autopilot1.16.0--

Explore more