Critical Zero-Day in Global SATCOM Systems Exploited by Multiple State Actors
A critical remote code execution vulnerability in Viasat and Iridium satellite communication firmware has been independently discovered and weaponized by at least three nation-state cyber units, affecting military and civilian SATCOM globally.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Geography:
- Russia
- CVE:
- CVE-2026-1847
- Source:
- Multiple Intelligence Sources
- Read Time:
- 6 min
Overview
Multiple intelligence sources confirm that a critical zero-day vulnerability (CVE-2026-1847) in satellite communication firmware has been independently weaponized by at least three nation-state actors.
Vulnerability Details
- Type: Remote Code Execution via buffer overflow in telemetry parsing
- CVSS Score: 9.8 (Critical)
- Affected Systems: Military and civilian SATCOM terminals
- Exploitation: No user interaction required
Impact Assessment
This vulnerability allows attackers to:
- Intercept encrypted satellite communications
- Inject false telemetry data
- Disable satellite terminals remotely
- Establish persistent backdoors in satellite ground stations
Mitigation
No patch is currently available. Organizations should implement network-level mitigations and monitor SATCOM terminal behavior for anomalies.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Vulnerability CVE-2026-93616 Exploited in Check Point Security Management Infrastructure

Check Point Management Server Zero-Day Exploited by Ransomware Gangs

