PX4
9 CVEs tracked since 2026. Since Mar 2026, none of them reached CISA KEV.
PX4 CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-03 | 9 | 0 |
Products
The products that kept showing up in PX4's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting PX4.
- CVE-2026-86714PX4 Autopilot through 1.17.0 Stack Buffer Over-read via netman5.4
- CVE-2026-86713PX4 Autopilot through 1.17.0 Use-After-Free in load_mon7.1
- CVE-2026-86097PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select6.5
- CVE-2026-86096PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup5.9
- CVE-2026-84698PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size6.5
- CVE-2026-1579PX4 Autopilot Missing authentication for critical function9.8
- CVE-2026-32743PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling6.5
- CVE-2026-32724PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition5.3
- CVE-2026-32713PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors4.3
- CVE-2026-32709PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)5.4
- CVE-2026-32708Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)7.8
- CVE-2026-32707PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop5.2
- CVE-2026-32706PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet7.1
- CVE-2026-32705PX4 autopilot BST Device Name Length Can Overflow Driver Buffer6.8
- CVE-2025-15150PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow5.3
The record
- Peak rank
- #144 in Mar 2026
- Busiest month shown
- Mar 2026, 9 CVEs
- Months with a KEV entry
- 0 since Mar 2026
- Monthly snapshots
- 1 since 2026