CVE Tools
Back to feed
Research PX4 Autopilot ics-ot-iot PX4

Aviation cyber risk sits on the ground, the blindness sits in the air

Help Net Security·By Mirko Zorz··6 min read
CVE Tools coverage

Eliran Almong, CEO of Cyviation, highlights that most aviation cyber losses stem from ground operations—such as reservations, MRO IT, and airport systems—rather than airborne threats. Despite the hype around 'hacking a plane,' real risks lie in unsecured data flows and outdated protocols like GNSS jamming, which evade traditional monitoring tools. A critical vulnerability, CVE-2026-1579, was recently disclosed in PX4 Autopilot, allowing attackers to send unsigned commands via MAVLink. This flaw underscores the broader issue of unauthenticated communication channels in aviation systems. Almong emphasizes the need for better visibility into both ground infrastructure and aircraft data chains, advocating for digital twins and rigorous inventory management.