Critical PX4 Autopilot flaw lets attackers hijack drones
Key Takeaways A critical vulnerability, CVE-2026-1579, has been identified in the PX4 Autopilot software, widely used in drones and autonomous vehicles. The flaw, scoring 9.8 on the CVSS v3 scale,...
Key Takeaways
- A critical vulnerability, CVE-2026-1579, has been identified in the PX4 Autopilot software, widely used in drones and autonomous vehicles.
- The flaw, scoring 9.8 on the CVSS v3 scale, allows unauthenticated attackers with MAVLink interface access to execute arbitrary commands, potentially hijacking drone operations.
- The specific version affected is PX4 Autopilot v1.16.0_SITL_latest_stable.
- While no in-the-wild exploitation is known, CISA has issued an advisory urging immediate defensive measures, including network segmentation and secure remote access.
A severe security vulnerability in the popular PX4 Autopilot software could allow unauthorized individuals to gain complete control over drones and other autonomous systems. This critical flaw poses a significant risk to various sectors, including critical infrastructure.
Table Of Content
The Cybersecurity and Infrastructure Security Agency (CISA) issued an Industrial Control Systems (ICS) advisory on March 31, 2026, alerting operators to the serious implications of this newly discovered weakness.
Headquartered in Switzerland, the PX4 Autopilot project develops open-source flight control software that sees extensive deployment in drones and autonomous vehicles globally. Its widespread adoption means this vulnerability could directly impact critical infrastructure, particularly within Transportation Systems, Emergency Services, and the Defense Industrial Base sectors.
PX4 Autopilot Vulnerability Details
Designated as CVE-2026-1579, this security defect carries a critical CVSS v3 score of 9.8. The core problem lies in a fundamental lack of authentication for a crucial function within the system.
Should an attacker manage to access a drone’s MAVLink interface—the primary communication protocol for commands and telemetry—they can exploit this weakness. This allows them to bypass existing security checks and execute arbitrary shell commands without needing any cryptographic authentication.
Essentially, an unauthorized user can run any system command they wish directly on the drone’s operating system. This level of access grants them the ability to manipulate flight paths, initiate crashes, intercept sensitive data, or completely lock legitimate operators out of the system.
The specific version confirmed to be vulnerable is PX4 Autopilot v1.16.0_SITL_latest_stable. Security researcher Dolev Aviv of Cyviation initially discovered and reported this vulnerability to CISA.
Fortunately, CISA has indicated that there is currently no known public exploitation of this flaw in active attacks.
What You Should Do
To safeguard drone fleets and critical infrastructure, CISA advises organizations to implement immediate protective measures:
- Ensure all control system devices have minimal network exposure and are never directly accessible from the public internet.
- Position control system networks and remote devices behind robust firewalls, completely isolating them from corporate business networks.
- Mandate the use of secure, fully updated Virtual Private Networks (VPNs) for any remote access to drone control systems.
- Perform a thorough risk assessment before deploying new defensive measures to prevent operational disruptions.
- Educate staff on identifying and resisting social engineering attacks, as phishing is often an initial vector for network compromise.
- Continuously monitor CISA alerts and apply official vendor patches as soon as they become available to secure autonomous fleets.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.