CVE-2026-38971: Ardupilot Arduplane

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().

Affected products

  • Ardupilot Arduplane: up to and including 4.6.3

Published 2026-07-02. Last modified 2026-07-09.