The Cybersecurity and Infrastructure Security Agency (CISA) released an Industrial Control Systems (ICS) advisory on March 31, 2026, warning operators about this severe flaw.
The PX4 Autopilot project, headquartered in Switzerland, provides open-source flight control software for drones and autonomous vehicles deployed worldwide.
Because of its massive adoption, this vulnerability directly threatens critical infrastructure, particularly within the Transportation Systems, Emergency Services, and Defense Industrial Base sectors.
Tracked as CVE-2026-1579, this security flaw carries a near-maximum CVSS v3 score of 9.8, classifying it as critical. The core issue stems from the absence of an authentication mechanism for a critical function.
If an attacker successfully gains access to the drone’s MAVLink interface, the primary communication protocol used for transmitting commands and telemetry, they can exploit this weakness to bypass security checks.
Once connected, the attacker can execute arbitrary shell commands without needing any cryptographic authentication.
In simple terms, an unauthenticated user can run any system command they choose directly on the drone’s operating system.
This grants them the power to alter flight paths, force crashes, intercept data, or completely lock legitimate operators out of the system.
The specific version currently known to be affected is PX4 Autopilot v1.16.0_SITL_latest_stable. Security researcher Dolev Aviv from Cyviation originally discovered and reported this vulnerability to CISA.
Fortunately, CISA notes that there is currently no known public exploitation targeting this flaw in the wild.
To protect drone fleets and infrastructure, CISA recommends that organizations take immediate defensive measures:
Because attackers often use phishing to gain initial access to networks, CISA also advises organizations to train staff to resist social engineering attacks.
Operators should continuously monitor CISA alerts and apply official vendor patches as soon as they become available to secure their autonomous fleets.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Critical PX4 Autopilot Vulnerability Let Attackers Gain Control Over the Drones appeared first on Cyber Security News.
An Evansville, Indiana woman has been arrested on multiple neglect charges after police say two…
Ever felt like there just aren’t enough hours in your day? I used to drown…
AI agents are autonomous operators, accessing applications, retrieving data, chaining tools, and executing tasks across…
Most AI transformation advice tells leaders what to do. Build the data infrastructure, invest in…
Ever felt like there just aren’t enough hours in your day? I used to drown…
AI agents are autonomous operators, accessing applications, retrieving data, chaining tools, and executing tasks across…
This website uses cookies.