CVE-2026-86096EPSS p24.2%

CVE-2026-86096CVE-2026-86096

Description

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations.

Scoring

CVSS 5.9 ()
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS0.33% probability of exploitation · percentile 24.2% · 2026-10-05T12:00:23Z
Last modified2026-09-10
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.