THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-1579 (CRITICAL 9.8) — The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with acces

[NVD] CVE-2026-1579 (CRITICAL 9.8) — The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with acces

lownvdPublished 2026-03-31

CVE-2026-1579 CVSS: 9.8 CRITICAL Published: 2026-03-31T21:16:27.897

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink interface. PX4 provides MAVLink 2.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1579