PatchSiren cyber security CVE debrief
CVE-2026-67975 NASA CVE debrief
CVE-2026-67975 is a HIGH-severity vulnerability in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. The vulnerability has a CVSS score of 7.5. This issue is related to incorrect access control, which can lead to unauthorized modifications. Affected organizations should prioritize verification of their inventory and apply compensating controls to limit exposure. The NASA cFS repository and issue tracking should be reviewed for additional context. Evidence is limited; further verification is recommended. Organizations should verify their inventory and apply compensating controls to limit exposure. The CVE record was published on 2026-08-03T22:16:51.613Z and has not been modified since then. To address this vulnerability, organizations should focus on verifying their inventory of NASA cFS v7.0.1 installations, applying compensating controls, and monitoring for suspicious activity. Security teams should also review relevant logs for exposed assets that need extra review. Given the limited evidence, a thorough review of the NASA cFS repository and issue tracking is necessary to understand the full scope of the vulnerability. Additionally, organizations should assess potential exposure and implement mitigations as needed. This includes reviewing current deployments, assessing potential exposure, and implementing mitigations as needed.
- Vendor
- NASA
- Product
- cFS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-08-06
Who should care
Organizations using NASA cFS v7.0.1, particularly those in critical infrastructure or aerospace sectors, should be aware of this vulnerability and take steps to verify their inventory and apply compensating controls. This includes reviewing their current deployments, assessing potential exposure, and implementing mitigations as needed. Security teams should also monitor for TO_LAB add/remove subscription commands and review relevant logs for exposed assets that need extra review.
Technical summary
CVE-2026-67975 is a HIGH-severity vulnerability in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. The vulnerability has a CVSS score of 7.5. This issue is related to incorrect access control, which can lead to unauthorized modifications. Affected organizations should prioritize verification of their inventory and apply compensating controls to limit exposure.
Defensive priority
Organizations using NASA cFS v7.0.1 should prioritize verification of their inventory and apply compensating controls to limit exposure.
Recommended defensive actions
- Verify inventory of NASA cFS v7.0.1 installations
- Apply compensating controls to limit exposure
- Monitor for TO_LAB add/remove subscription commands
- Review relevant logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE description notes incorrect access control in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. Evidence is limited; further verification is recommended. Organizations should verify their inventory and apply compensating controls to limit exposure. The NASA cFS repository and issue tracking should be reviewed for additional context.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T22:16:51.613Z and has not been modified since then.