


Perceptive Security
SOC/SIEM Consultancy

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reacha…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 23:02:24
Source:
nvd.nist.gov
Critical Infrastructure, Zero-Day Vulnerabilities
CVE-2026-18064 describes an incomplete fix for a prior vulnerability (CVE-2026-15352) in the NASA core Flight System (cFS) Health and Safety (HS) application. A separate NULL pointer dereference remains reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could crash the HS application. The resulting crash causes a denial-of-service condition and a processor reset. This vulnerability is particularly significant given its presence in aerospace/critical infrastructure software. CISA has published an ICS advisory (icsa-26-211-06) related to this issue. The incomplete patch nature of the vulnerability suggests remediation efforts require further attention.
Technical details
Mitigation steps:
Affected products:
NASA core Flight System (cFS) Health and Safety (HS) application 7.0.1 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18064
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-06.json
https://github.com/nasa/HS
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
