CVE-2026-67975

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.

Published 2026-08-03. Last modified 2026-08-31.