The text messaging link that airline pilots and air traffic controllers use alongside voice radio carries its messages in the clear and never checks who sent them. CISA published five CVEs on 7 August describing what that makes possible, and confirmed there is currently no fix for any of them.
The advisory, tracked as ICSA-26-219-01, covers Controller Pilot Data Link Communications, or CPDLC, carried over the ATN-B1 standard. CPDLC is the system that lets a controller send a routine instruction as text rather than reading it over a congested radio channel. Martin Strohmeier of Armasuisse reported the issues to CISA. The full advisory is published on CISA's site.
CISA is explicit about the ceiling on this: the flaws do not constitute an unsafe aircraft condition. What they can do is degrade the margins around safety, by raising workload, delaying safety critical instructions and reducing situational awareness in the cockpit and on the ground.
What the five issues allow
Two are rated 7.1 and treated as high severity. CVE-2025-71409 covers the missing authentication itself: because Very High Frequency data link messages are not authenticated, a rogue ground station can inject CPDLC messages, which CISA says can lead to unexpected or misleading clearances and pilot confusion. CVE-2025-71412 covers injection of false emergency or status messages, which CISA warns may cause misallocation of resources, operational confusion and improper responses from flight crews, controllers and ground operations.
The remaining three are denial of service issues, scored 5.3 under CVSS 3.1 and 6.0 under CVSS 4.0. CVE-2025-71410 covers disconnect and malformed link control frames that terminate sessions, forcing a reversion to voice communication and increasing controller workload. CVE-2025-71411 covers broadcast control frames that can disconnect multiple aircraft at once, delaying clearances. CVE-2025-71413 covers malformed or out of sequence frames at the link control and X.25 layers, which cause repeated session resets.
All five are listed as affecting every version of ATN-B1 CPDLC, deployed worldwide.
How worried to be
Less than the CVE count suggests, on CISA's own framing. The agency states that the flaws are exploitable in a lab environment but require very specific conditions, are unlikely to be exploited outside a lab setting, and carry high attack complexity. No public exploitation targeting them has been reported to CISA.
The attacks are also all carried out over radio, which means physical proximity to the aircraft or the ground station rather than an internet connection. That is a meaningful barrier, and it is why the scores are what they are.
What operators can do
There is no patch, and CISA lists no mitigation for any of the five. This is a property of a protocol designed decades ago for an environment where transmitting on aviation frequencies at all was the hard part, and changing it means changing an international standard rather than shipping an update.
What is left is procedural. Voice communication remains the fallback when a datalink session drops, which is exactly what the denial of service issues force. CISA asks organizations that observe suspected malicious activity to follow their internal procedures and report findings to the agency so they can be correlated against other incidents.
The pattern is a familiar one in systems built before anyone modelled a hostile transmitter, from fuel terminal controllers shipping with an open root debug port to the long history of attacks on space systems moving from television pranks to wiper malware.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.