VulnSea

px4 has 5 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: PX4-Autopilot (4), autopilot (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
4 prev 1

Products

  • PX4-Autopilot 4
  • autopilot 1
5
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

px4 vulnerabilities

CVEs affecting px4, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-86714Medium· 5.4
2w ago

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read be…

SunlitPX4 · PX4-AutopilotEPSS 0.21%via NVD
CVE-2026-86713High· 7.1PoC
2w ago

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attack…

MidnightPX4 · PX4-AutopilotEPSS 0.37%via NVD
CVE-2026-86096Medium· 5.9
2w ago

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands t…

SunlitPX4 · PX4-AutopilotEPSS 0.22%via NVD
CVE-2026-86097Medium· 6.5PoC
2w ago

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or…

TwilightPX4 · PX4-AutopilotEPSS 0.24%via NVD
CVE-2026-1579Critical· 9.8
5mo ago

The MAVLink communication protocol does not require cryptographic authentication by default

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be s…

Midnightpx4 · autopilotEPSS 0.93%via NVD
px4 vulnerabilities (CVEs) · VulnSea