Government Advisory

Aviation Alert: Legacy Air Traffic Communication System Vulnerable to Message Injection Attacks

CISA · 7 Aug 2026
Key Takeaway If your business still relies on older systems or protocols without built-in authentication and encryption, prioritise upgrading them, as unauthenticated communication channels remain a common entry point for attackers across every industry.

CISA has issued an advisory covering five vulnerabilities affecting Controller-Pilot Data Link Communications (CPDLC) over the ATN-B1 standard, a system used for text-based communication between air traffic controllers and pilots. The core issue is that ATN-B1 CPDLC relies on legacy, unencrypted, unauthenticated radio frequency links, meaning messages are sent as plain text without verification of the sender.

Research has shown these weaknesses could allow attackers to inject unauthorized messages into the communication channel, trigger denial-of-service conditions, or force session resets. Importantly, CISA notes these flaws do not create an unsafe aircraft condition on their own, but they can degrade safety margins by increasing controller and pilot workload, delaying critical instructions, and reducing situational awareness during flight operations.

While this advisory is specific to aviation infrastructure rather than typical small business IT systems, it's a useful reminder of a broader lesson: systems built on old, unauthenticated communication protocols remain vulnerable no matter how critical the industry. Businesses relying on legacy systems, whether in operational technology, point-of-sale, or internal communications, should take note that unauthenticated, unencrypted channels are a persistent and serious risk across sectors.

aviation security critical infrastructure CISA advisory legacy systems authentication vulnerabilities

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.