PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67975 NASA CVE debrief

CVE-2026-67975 is a HIGH-severity vulnerability in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. The vulnerability has a CVSS score of 7.5. This issue is related to incorrect access control, which can lead to unauthorized modifications. Affected organizations should prioritize verification of their inventory and apply compensating controls to limit exposure. The NASA cFS repository and issue tracking should be reviewed for additional context. Evidence is limited; further verification is recommended. Organizations should verify their inventory and apply compensating controls to limit exposure. The CVE record was published on 2026-08-03T22:16:51.613Z and has not been modified since then. To address this vulnerability, organizations should focus on verifying their inventory of NASA cFS v7.0.1 installations, applying compensating controls, and monitoring for suspicious activity. Security teams should also review relevant logs for exposed assets that need extra review. Given the limited evidence, a thorough review of the NASA cFS repository and issue tracking is necessary to understand the full scope of the vulnerability. Additionally, organizations should assess potential exposure and implement mitigations as needed. This includes reviewing current deployments, assessing potential exposure, and implementing mitigations as needed.

Vendor
NASA
Product
cFS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-06
Advisory published
2026-08-03
Advisory updated
2026-08-06

Who should care

Organizations using NASA cFS v7.0.1, particularly those in critical infrastructure or aerospace sectors, should be aware of this vulnerability and take steps to verify their inventory and apply compensating controls. This includes reviewing their current deployments, assessing potential exposure, and implementing mitigations as needed. Security teams should also monitor for TO_LAB add/remove subscription commands and review relevant logs for exposed assets that need extra review.

Technical summary

CVE-2026-67975 is a HIGH-severity vulnerability in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. The vulnerability has a CVSS score of 7.5. This issue is related to incorrect access control, which can lead to unauthorized modifications. Affected organizations should prioritize verification of their inventory and apply compensating controls to limit exposure.

Defensive priority

Organizations using NASA cFS v7.0.1 should prioritize verification of their inventory and apply compensating controls to limit exposure.

Recommended defensive actions

  • Verify inventory of NASA cFS v7.0.1 installations
  • Apply compensating controls to limit exposure
  • Monitor for TO_LAB add/remove subscription commands
  • Review relevant logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE description notes incorrect access control in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. Evidence is limited; further verification is recommended. Organizations should verify their inventory and apply compensating controls to limit exposure. The NASA cFS repository and issue tracking should be reviewed for additional context.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T22:16:51.613Z and has not been modified since then.