CVE-2026-72579: Nasa Hypercp

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher's workstation.

Affected products

Published 2026-08-10. Last modified 2026-08-28.