PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command. The vulnerability fails to validate interface name length, allowing attackers to supply interface names of 74 bytes or more via the -i option. This can lead to reading beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
The CVE-2026-84698 vulnerability involves a heap buffer overflow in the sd_bench command of PX4 Autopilot, a popular open-source flight stack used in drones, robots, and other unmanned systems. The vulnerability is caused by writing a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially ex [truncated]
CVE-2026-1579 describes a high-impact authentication weakness in PX4 Autopilot deployments that use MAVLink without 2.0 message signing. According to CISA, when signing is not enabled, an unauthenticated party with access to the MAVLink interface can send messages, including SERIAL_CONTROL, which can provide interactive shell access. PX4’s mitigation is to enable MAVLink 2.0 message signing so unsigned me [truncated]