Ardupilot is an autopilot and flight-control software platform used across unmanned aircraft and rover systems, with its narrow product footprint centered on the APWeb component. Observed vulnerabilities cluster around input-handling weaknesses such as improper input validation and out-of-bounds writes, which are relevant to the safety-critical nature of flight-control logic; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ardupilot over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-38971CRITICAL ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control(). | Jul 2, 2026 | 9.1 | 36 | NO | NO |
CVE-2022-28711CRITICAL A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac - master branch 46177cb9. A specially-crafted HTTP request ca | Apr 14, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ardupilot.
Media articles that mention a CVE ID that affects a product developed by Ardupilot — matched by CVE ID, not by vendor name.