Critical PX4 Autopilot Vulnerability Allows Drone Control Takeover
Article Content
- •CISA issued a high-priority alert for CVE-2026-1579 affecting PX4 Autopilot.
- •The vulnerability allows complete control over drones, posing risks to critical infrastructure.
- •Operators are urged to assess their systems and implement security measures immediately.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert regarding a critical vulnerability in the PX4 Autopilot system, tracked as CVE-2026-1579, published on March 31, 2026. This flaw enables malicious actors to gain complete control over unmanned aerial vehicles (UAVs) and drones, impacting vital infrastructure sectors. The vulnerability poses a significant risk to operators who rely on PX4 Autopilot software, which is widely used in drone operations. CISA's advisory emphasizes the urgent need for operators to assess their systems and implement necessary security measures. The flaw is categorized with a near-maximum Common Vulnerability Scoring System (CVSS) score, indicating its severity. As of now, no specific exploitation cases have been reported, but the potential for abuse remains high.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Cybersecurity and Infrastructure Security Agency and CVE-2026-1579 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…