28/09/2026
United States: The US Government Accountability Office (GAO) has identified cybersecurity gaps in FAA systems supporting aircraft communications, air traffic control and navigation, warning that weaknesses in risk assessments, security documentation and real-time monitoring could expose the National Airspace System to spoofing, jamming and interference. The 58-page report was released on 21 September 2026.
GAO found that the FAA lacks continuous 24/7 monitoring for spectrum-related threats and identified security deficiencies across eight NAS systems. It also highlighted vulnerabilities in ACARS and CPDLC, including limited authentication and encryption that could allow interception, spoofing or message manipulation. FAA is testing newer Internet Protocol Suite technology but has no documented full deployment timeline.
GAO issued nine recommendations covering risk assessments, real-time monitoring, interagency coordination, information sharing and stronger ACARS/CPDLC protections. The Department of Transportation concurred with all nine recommendations. GAO stressed that the FAA has not experienced a successful cyberattack resulting in safety impacts, but said evolving threats make stronger aviation cybersecurity increasingly important.
đź”— Article Link In Comments
Video: