LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32708

CVE-2026-32708 - Vulnerability Analysis

HighCVSS: 7.8

Last Updated: March 16, 2026

PX4 autopilot - Denial of Service

Published: March 16, 2026Updated: March 16, 2026PoC Available

Overview

PX4 autopilot < 1.17.0-rc2 contains a stack overflow caused by unbounded stack allocation from incoming Zenoh uORB subscriber payload length, letting remote Zenoh publishers crash the Zenoh bridge task, exploit requires sending oversized fragmented messages.

Severity & Score

Severity: High
CVSS Score: 7.8
EPSS Score: 1.3%(Probability of exploitation in next 30 days)

Impact

Remote attackers can cause a stack overflow leading to a crash of the Zenoh bridge task, resulting in denial of service.

Mitigation

Update to version 1.17.0-rc2 or later.

Social Media Activity(3 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

🟠 CVE-2026-32708 - High (7.8) PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32708/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

🟠 CVE-2026-32708 - High (7.8) PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32708/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
Offensive Sequence
Offensive Sequence
@offseq
Mar 14, 2026

🚁 CVE-2026-32708 (HIGH): Stack-based buffer overflow in PX4-Autopilot (<1.17.0-rc2) via Zenoh uORB subscriber. Exploitable w/ local privileges; could crash or compromise drones. Upgrade ASAP. https://radar.offseq.com/threat/cve-2026-32708-cwe-121-stack-based-buffer-overflow-a8d143e4 #OffSeq #DroneSecurity #CVE #Infosec

View original post

Details

CVE ID
CVE-2026-32708
Severity
High
CVSS Score
7.8
Type
buffer_overflow
Status
confirmed
EPSS
1.3%
Social Posts
3

CWE

  • CWE-121

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1.3%Probability of exploitation in the next 30 days