CISA flags NASA cFS HS denial-of-service flaw
Availability is the issue here: exposed cFS HS deployments can be crashed without credentials or user interaction.
TL;DR
CISA published CVE-2026-15352 for NASA Core Flight System Health & Safety application versions before v7.0.1. The NULL pointer dereference can crash the HS application during Housekeeping Telemetry processing, causing denial of service. Organizations running cFS HS modules, including government and defense-industrial-base environments with transportation-system exposure, should update to v7.0.1. CISA reports no known public exploitation.
CISA’s advisory is a standard ICS patch item, which means the Monday work is inventory and update discipline, not a new compliance program. CVE-2026-15352 affects NASA Core Flight System Health & Safety application versions earlier than v7.0.1 and can cause a segmentation fault during Housekeeping Telemetry processing. The ratings, CVSS 3.1 at 7.5 and CVSS 4.0 at 8.2, reflect the part that matters operationally: the vector is network-accessible and requires no privileges or user interaction. CISA says NASA recommends updating to v7.0.1, and CISA repeats the usual ICS guidance to reduce network exposure, segment control systems from business networks, and assess operational impact before defensive changes. No known public exploitation has been reported to CISA.
Published ·Deep Fathom