CVE-2026-1579
CVSS 9.8 CRITICAL: the MAVLink communication protocol does not require cryptographic authentication by default.
Vulnerabilities & Exploits · IoT / OT Attack
PX4 Autopilot — flight control software for drones and unmanned vehicles — accepts unauthenticated SERIAL_CONTROL MAVLink messages that can spawn an interactive shell. The flaw appears in Autopilot v1.16.0_SITL_latest_stable and is tracked as CVE-2026-1579. MAVLink does not require cryptographic authentication by default, so deployments with MAVLink 2.0 message signing disabled will accept unsigned SERIAL_CONTROL messages. Affected sectors include transportation, defense, and other critical infrastructure where MAVLink interfaces are reachable.
1 source · Mar 31
CVSS 9.8 CRITICAL: the MAVLink communication protocol does not require cryptographic authentication by default.
CISA Advisories
PX4 Autopilot | CISA
PX4 Autopilot Summary Successful exploitation of this vulnerability could allow an attacker with access to the MAVLink interface to execute arbitrary shell commands without cryptographic authentication.
originalPart of the PlainSec briefing for 2026-04-01
Every edition of this story: Unauthenticated Shell via MAVLink Enables Remote Command Execution