HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical NULL Pointer Dereference (CVE‑2026‑18064) in NASA cFS Health & Safety Application Enables DoS and Processor Reset

NASA’s Core Flight System Health & Safety application (≤ v7.0.1) contains a CVE‑2026‑18064 NULL‑pointer dereference that can crash the system, causing denial‑of‑service and a processor reset. For SOC 2‑ready organizations, the flaw highlights the need for continuous control mapping and auditable remediation evidence.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Critical NULL Pointer Dereference (CVE‑2026‑18064) in NASA cFS Health & Safety (HS) Application Enables DoS and Processor Reset

What It Is — The NASA Core Flight System (cFS) Health & Safety (HS) application (≤ v7.0.1) contains an incomplete fix for CVE‑2026‑15352 that leaves a separate NULL‑pointer dereference reachable. Triggering the vulnerable command can crash the HS process, causing a denial‑of‑service condition and a full processor reset.

Exploitability — CVSS v3 7.5 (High). No public exploit code is known, but the vulnerability is exploitable by an attacker who can issue the specific command under the required conditions (e.g., via a compromised ground‑station link).

Affected Products — NASA Core Flight System (cFS) Health & Safety (HS) Application, versions ≤ 7.0.1.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: The flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of remediation must be captured to demonstrate control effectiveness.
  • Continuous Evidence: Enterprises that rely on cFS for mission‑critical transport systems need auditable proof that vulnerable firmware is patched or mitigated, otherwise they risk non‑compliance findings during a SOC 2 audit.
  • Due Diligence: Documenting the vulnerability, the temporary mitigation, and the timeline for the official NASA fix satisfies vendor‑risk and supply‑chain due‑diligence requirements increasingly demanded by regulators and customers.

Recommended Actions

  • Apply the NASA patch as soon as it is released; track patch status in your configuration‑management database (CMDB).
  • Temporarily disable the vulnerable command or restrict its execution to authenticated, least‑privilege accounts.
  • Map the issue to SOC 2 CC6.1/CC7.1, capture remediation evidence (patch tickets, configuration changes) in a tamper‑evident repository.
  • Update incident‑response playbooks to include detection of the specific command failure and escalation procedures.
  • Monitor for any anomalous command traffic from ground‑station interfaces.

Source: CISA Advisory – ICSA‑26‑211‑06

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →