Security advisory · checked September 24, 2026
Three public CVE records name Bluetooth, Wi-Fi and local-service issues across specified firmware ranges for 16 DJI consumer drones. The important context is proximity: these records do not describe a stranger anywhere on the internet taking over every DJI aircraft.
Two of the August 2026 records depend on nearby Bluetooth or BLE access; the third requires an existing aircraft internal-network or local USB path. Owners should check and update the aircraft, remote controller and DJI Fly to the latest versions currently offered by DJI, without assuming that one particular “next” firmware number is the definitive fix.
Start with what the records do—and do not—prove
Evidence Status: Public CVE Records, Not a DJI Fix Bulletin
CVE-2026-77812, CVE-2026-78306 and CVE-2026-78251 are published records assigned by CIRCL. NVD displays them, but marks all three Deferred, meaning they have not been prioritized for NVD enrichment. The affected-version lists and CVSS v4 scores shown there are source-supplied record data, not a separate NVD laboratory assessment.
As of our September 24 review, we did not find a public DJI security bulletin naming these CVEs or declaring a specific fixed firmware. That changes the wording owners should rely on: the records tell us which versions are listed as affected, while DJI's official support workflow tells owners to install the latest available update.
Precise wording: “The public CVE record lists firmware through version X as affected.” That is not the same as saying “X+1 is confirmed fixed” or “every later build is safe.”
Three records, three different access conditions
DJI 2026 CVE Risk Context
The scores are useful for technical triage, but the access conditions tell an owner what kind of exposure is actually being discussed.
| CVE | Public date | Required proximity or access | Primary concern | Source CVSS v4 |
|---|---|---|---|---|
| CVE-2026-77812 | Aug. 21 | Nearby BLE range while a normal Wi-Fi/QuickTransfer connection is established | Wi-Fi credential and trusted-identifier exposure | 9.4 Critical |
| CVE-2026-78306 | Aug. 24 | Nearby Bluetooth range | Wireless configuration or connection integrity | 8.5 High |
| CVE-2026-78251 | Aug. 27 on NVD | Existing aircraft internal-network or local USB RNDIS path | Storage exhaustion affecting logs, records or future updates | 9.3 Critical |
Dates above are NVD publication dates. The CVE Program record for 78251 carries an earlier August 24 publication timestamp; this timing difference does not change the technical scope.
Observe a normal transfer setup
The record describes cleartext BLE data during Wi-Fi/QuickTransfer establishment. It is a nearby-radio scenario, not an open internet path.
Reach the local wireless interface
The record concerns insufficient authentication for control functions that can change wireless settings or disrupt a connection.
Already have deeper local access
The actor first needs an aircraft internal-network or USB-network path before the described storage-exhaustion condition becomes relevant.
Check the model and the number
DJI Consumer Drone Affected-Version Matrix
All three CVE Program records list the same 16 model/version pairs. Compare the full firmware number—similar model names do not share one universal threshold.
Current high-interest models
| DJI model | Public CVE record lists affected through | Owner action |
|---|---|---|
| DJI Mavic 4 Pro | 01.00.0500 | Check the latest aircraft update offered by DJI. |
| DJI Mini 5 Pro | 01.00.0600 | Check the latest aircraft update offered by DJI. |
| DJI Air 3S | 01.00.1400 | Check the latest aircraft update offered by DJI. |
| DJI Neo 2 | 01.00.0500 | Check the latest aircraft update offered by DJI. |
| DJI Flip | 01.00.1200 | Check the latest aircraft update offered by DJI. |
| DJI Avata 360 | 01.00.0300 | Check the latest aircraft update offered by DJI. |
| DJI Avata 2 | 01.00.0400 | Check the latest aircraft update offered by DJI. |
Older or legacy affected models
| DJI model | Public CVE record lists affected through | DJI model | Public CVE record lists affected through |
|---|---|---|---|
| DJI Neo | 01.00.0400 | DJI Air 3 | 01.00.1600 |
| DJI Mavic 3 | 01.00.1400 | DJI Mavic 3 Classic | 01.00.0800 |
| DJI Mavic 3 Pro | 01.01.0700 | DJI Mini 2 | 01.07.0200 |
| DJI Mini 3 | 01.00.0500 | DJI Mini 3 Pro | 01.00.0900 |
| DJI Mini 4 Pro | 01.00.1100 | No additional model in this group | |
Version source: official CVE Program records for 77812, 78306 and 78251. “Affected through” is record language, not a SpeedyDrone firmware test.
Why Bluetooth and Wi-Fi appear together
What QuickTransfer Has to Do with This
DJI's official QuickTransfer guide explains that supported aircraft use Bluetooth and Wi-Fi to connect with DJI Fly for high-speed file transfer. Bluetooth discovery and connection state, the aircraft Wi-Fi network and the app therefore sit inside the same normal transfer workflow.
That explains why wireless authentication and credential handling matter. It does not mean QuickTransfer itself is universally compromised, and it does not justify publishing capture instructions or a reproduction recipe.
A score is not a forecast
CVSS Severity Does Not Equal Real-World Likelihood
A Critical or High CVSS result describes potential technical impact under the scoring assumptions. It does not say how often a typical owner will meet the attack conditions, whether an exploit has been packaged for broad use or whether the issue is currently being used in the wild.
As checked on September 24, none of these three CVEs appeared in the CISA Known Exploited Vulnerabilities catalog. The CISA SSVC enrichment displayed in the NVD records also said `Exploitation: none`. That is useful context, but it is not proof that exploitation is impossible or has never occurred.
Measured conclusion: we found no reliable public evidence of widespread active exploitation in the reviewed primary sources. Owners should still update, because absence from a known-exploited list is not a substitute for remediation.
The owner response is straightforward
What DJI Owners Should Check Now
Install the latest update DJI currently offers for the exact aircraft.
Update DJI RC, RC Pro or the controller used with the aircraft.
Use DJI's current official app distribution and confirm the app is current.
Restart, reconnect aircraft and controller, then confirm installed versions.
DJI's firmware guidance recommends updating promptly when the app displays a new version. Do not delay old firmware indefinitely only to preserve a familiar behaviour: the trade-off can include security, not just missing features.
You do not need to stop using QuickTransfer. If an aircraft is not yet current, avoid leaving wireless-transfer mode active longer than necessary in crowded public environments. USB-C or microSD transfer is a reasonable alternative for important footage while you complete updates.
What we are not saying
This Advisory Does Not Mean Every DJI Drone Is Remotely Hijackable
- It does not mean every DJI drone can be controlled from anywhere.
- It does not mean every current firmware build is vulnerable.
- It does not mean every QuickTransfer session is compromised.
- It does not establish widespread active exploitation.
- It does not automatically include DJI Enterprise aircraft.
- It does not require owners to stop flying DJI drones.
Keep product families separate
Consumer CVE Scope Is Not an Enterprise Finding
The public affected list names consumer aircraft. It does not name Matrice, Dock or other DJI Enterprise platforms, so these records cannot be used to declare those products affected by the same issues.
Enterprise buyers still need a broader security process covering data flows, user roles, cloud and local operating modes, retention, incident response and procurement evidence. That separate decision belongs in our Drone Data Security Checklist for Canadian Government & Enterprise Buyers.
A fair view needs scope and time
How This Fits DJI's Broader Security Record
In May 2026, DJI published an authorized OnDefend assessment covering Air 3S and Matrice 4E. DJI said the independently conducted October 2025–March 2026 work found no Critical, High or Medium findings in scope, plus ten Low findings and thirteen observations.
That result is meaningful within its stated products, test window and methods. It cannot prove every DJI device or future firmware is vulnerability-free. The later CVE records do not erase the assessment either: together they show why product security is a continuing process rather than a permanent certificate.
Current models named in the records
Verified SpeedyDrone Product Links
These current SpeedyDrone listings match four high-interest models in the public affected list. Buying a current unit does not replace the version check—confirm the firmware offered by DJI during setup.
Exact listing identity and availability were checked September 24, 2026. Availability can change; no permanent-stock claim is made.
Frequently asked questions
DJI Drone Security Update FAQ
Is DJI Mavic 4 Pro affected?
The public CVE records list Mavic 4 Pro firmware through 01.00.0500 as affected. Check and install the latest version DJI currently offers rather than assuming one particular next version is the confirmed fix.
Is DJI Mini 5 Pro affected?
The public records list Mini 5 Pro firmware through 01.00.0600. Update the aircraft, its controller and DJI Fly, then reconnect and verify the installed versions.
Is DJI Air 3S affected?
The public records list Air 3S firmware through 01.00.1400. That threshold is public-record scope; owners should use the latest firmware currently offered by DJI.
Is DJI Neo 2 affected?
The public records list Neo 2 firmware through 01.00.0500. Confirm the exact model and full version number, because original Neo and Neo 2 have separate thresholds.
Can someone hack my DJI drone from anywhere?
These records do not describe that scenario. Two require nearby Bluetooth or BLE conditions; the third requires an existing aircraft internal-network or local USB path.
Should I stop using QuickTransfer?
No public evidence reviewed here supports a blanket stop. Keep the aircraft, controller and DJI Fly current; until then, avoid leaving transfer mode active unnecessarily in dense public spaces and use USB-C or microSD when that better fits the situation.
Are DJI Enterprise drones affected?
The named affected list does not include Matrice, Dock or other DJI Enterprise aircraft. These consumer CVE records cannot be used to infer that Enterprise products have the same issues.
Have these vulnerabilities been widely exploited?
As checked September 24, 2026, we found no reliable public evidence of widespread exploitation in the reviewed primary sources, and none appeared in CISA's KEV catalog. That is not a guarantee; updating remains the appropriate response.
Current Canadian catalogue
Browse DJI Consumer Drones at SpeedyDrone
Compare current Mini, Air, Mavic and other DJI consumer models, then complete the latest firmware check during setup.
Primary Sources
- NVD records: CVE-2026-77812, CVE-2026-78306 and CVE-2026-78251.
- DJI QuickTransfer guidance and DJI firmware update guidance.
- CISA Known Exploited Vulnerabilities Catalog.
- DJI's May 2026 OnDefend assessment announcement.
Last evidence review: September 24, 2026. Security records and firmware availability can change; this page should be rechecked at publication and whenever DJI releases relevant notes.


