THREAT OPS › Threat News › [NVD] CVE-2026-1579 (CRITICAL 9.8) — The MAVLink communication protocol does not require cryptographic
authentication by default. When MAVLink 2.0 message signing is not
enabled, any message -- including SERIAL_CONTROL, which provides
interactive shell access -- can be sent by an unauthenticated party with
acces
[NVD] CVE-2026-1579 (CRITICAL 9.8) — The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with acces
CVE-2026-1579 CVSS: 9.8 CRITICAL Published: 2026-03-31T21:16:27.897
The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink interface. PX4 provides MAVLink 2.
Indicators of compromise
- CVE-2026-1579cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1579