Back Feeds.Feedburner NASA ground control software vulnerability could allow spacecraft access
NASA's ground control software has a critical vulnerability that could allow third-party access to spacecraft, with further coverage provided by Tech Radar.
A browser-based variant of NASA's AMMOS Instrument Toolkit (AIT), specifically versions up to 2.5.1, has a critical vulnerability that could allow an unauthenticated attacker to issue commands to spacecraft and instruments, and potentially execute server-side scripts, as discovered by Cycode researchers. The flaw, disclosed on August 18, 2026, stems from the AIT-GUI running as a web server with an open network interface and lacking authentication, authorization, or cross-site request forgery (CSRF) protection. This allows attackers to exploit basic access-control failings, potentially enabling them to upload files, including malware, directly to NASA craft via a vulnerable browser session.
The attacker does not need to be on the same network, as access can be gained through an exposed port or by tricking an operator into visiting a malicious webpage. Cycode advises administrators to upgrade AIT-GUI to version 2.5.2, check console ports, and review command history.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
