Dronecode develops autopilot and communication firmware for small unmanned aircraft systems, with a narrow but strategically significant product portfolio centered on the PX4 drone autopilot and the Micro Air Vehicle Link protocol. Vulnerabilities affecting the vendor skew toward critical severity outcomes and reflect the memory-safety demands of embedded avionics code: the recurring weakness classes include classic and stack-based buffer overflows, out-of-bounds writes, race conditions, and improper value handling that arise from direct memory manipulation and concurrent access patterns in safety-critical flight control software. The exposure concentrates on core autopilot and communication products that are widely integrated into both commercial and defense unmanned systems, making flaws in this codebase consequential despite the narrow vendor footprint. Defenders should prioritize firmware inventory and validation for unmanned platforms that rely on these components; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dronecode over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32708HIGH PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds | Mar 13, 2026 | 8.0 | 28 | NO | NO |
CVE-2023-46256CRITICAL PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due t | Oct 31, 2023 | 9.8 | 27 | NO | NO |
CVE-2026-26742HIGH PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm l | Mar 10, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-26741HIGH PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" st | Mar 10, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-32743MEDIUM PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow through the MavlinkLogHandler, a | Mar 19, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-15150HIGH A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the fil | Dec 28, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-34125HIGH An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands. | Mar 9, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-10283CRITICAL The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibi | Aug 20, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10282CRITICAL The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity sp | Jul 3, 2020 | 9.8 | 24 | NO | NO |
CVE-2026-32706HIGH PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte | Mar 16, 2026 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dronecode.
Media articles that mention a CVE ID that affects a product developed by Dronecode — matched by CVE ID, not by vendor name.