CVE-2026-32743General(dronecode / px4_drone_autopilot)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dronecode px4_drone_autopilot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow through the MavlinkLogHandler, and are triggered via MAVLink log request. The LogEntry.filepath buffer is 60 bytes, but the sscanf function parses paths from the log list file with no width specifier, allowing a path longer than 60 characters to overflow the buffer. An attacker with MAVLink link access can trigger this by first creating deeply nested directories via MAVLink FTP, then requesting the log list. The flight controller MAVLink task crashes, losing telemetry and command capability and causing DoS. This issue has been fixed in this commit: https://github.com/PX4/PX4-Autopilot/commit/616b25a280e229c24d5cf12a03dbf248df89c474.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • px4_drone_autopilot

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-19); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
px4_drone_autopilot

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-21: 1Mentions · 2026-06-11: 2Mentions · 2026-10-07: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-19: 4Technical Details · 2026-06-11: 203-1903-2106-1110-07
Signal classification3 categories
General
457.1%
Disclosure
228.6%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure1General2Patch1
2026-03-211
General1
2026-06-112
Disclosure1General1
Full discourse8 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-32743 exposes critical buffer overflow in PX4 Autopilot affecting wide range of commercial drones. MAVLink protocol exploitation enables remote DoS via crafted file paths. #DFIR_Radar https://t.co/Kva2J6A8uN

    Post summary

    The tweet announces the discovery of a critical buffer overflow in PX4 Autopilot that allows remote denial-of-service attacks, but it does not provide any PoC, exploit code, active exploitation evidence, or patch information.

    10000139
    1.6K followersView on X
  • DailyCVE@dailycve

    🟠 PX4 Autopilot, Stack-based Buffer Overflow, #CVE-2026-32743 (Medium) -DC-Oct2026-2793 https://dailycve.com/px4-autopilot-stack-based-buffer-overflow-cve-2026-32743-medium-dc-oct2026-2793/

    0000031
    239 followersView on X
  • Israel@f1tym1
    General

    Analyzing CVE-2026-32743: PX4 MAVLink Buffer Overflow DoS https://ift.tt/6LHIKs7 Recent global conflicts have dramatically reshaped our understanding of security. The widespread deployment of commercially available “civilian” drones has proven that modern warfare is no longe…

    Post summary

    The post provides a high‑level analysis of CVE‑2026‑32743, noting it as a buffer‑overflow denial‑of‑service flaw in PX4 MAVLink, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000038
    996 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-32743 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32743 #CVE-2026-32743 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/YLwibK1fp6

    Post summary

    The tweet announces CVE-2026-32743 with a medium severity rating and links to the NVD entry, but provides no further technical details, exploits, or mitigation information.

    0000024
    108 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    Inductive Automation Ignition Software vulnerability could allow malicious code execution with elevated permissions. Users urged to update. CVE-2026-31969: HTSlib CRAM decoder heap buffer overflow may enable arbitrary code execution or system crashes. CVE-2026-32743: PX4 Autopilot affected by stack-based buffer overflow from improper MAVLink log request handling. CVE-2026-1276: IBM QRadar SIEM is vulnerable to cross-site scripting, risking arbitrary JavaScript injection by authenticated users. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #BlueTeam #DFIR

    Post summary

    The post announces several new CVEs and urges users to apply updates, focusing on patching rather than exploitation details.

    0000029
    49 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32743 PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow through the Mavlin… https://www.cve.org/CVERecord?id=CVE-2026-32743

    Post summary

    CVE‑2026‑32743 describes a stack‑based buffer overflow in PX4 autopilot stack versions 1.17.0‑rc2 and earlier, but no PoC, exploit, patch, or active exploitation claims are provided.

    00000111
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32743 Stack-Based Buffer Overflow in PX4 Autopilot via MAVLink Log Request https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32743 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces a stack‑buffer overflow vulnerability in PX4 Autopilot triggered by a MAVLink log request, but provides only the basic description without any exploitation, mitigation, or PoC details.

    0000037
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32743 - PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling Intel Report: https://ift.tt/2LaT96D

    Post summary

    Intel has announced a stack-based buffer overflow (CVE-2026-32743) in PX4 Autopilot, potentially enabling exploitation through oversized path inputs in MAVLink log requests.

    0000046
    335 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appdronecodepx4_drone_autopilot---
Appdronecodepx4_drone_autopilot1.17.0--
Appdronecodepx4_drone_autopilot1.17.0--
Appdronecodepx4_drone_autopilot1.17.0--
Appdronecodepx4_drone_autopilot1.17.0--

Explore more