A previously unknown software defect with an exposure window of about one millisecond caused the National Airspace System failure that disrupted UK aviation on 8 September, NATS said in a preliminary investigation summarized by UK Aviation News and FlightGlobal.
The report, published around 16 September, traces how a valid manual request to allocate or reassign an aircraft squawk code was interrupted by a higher-priority request. When processing resumed, legacy software corrupted flight data inside the NATS National Airspace System. Controllers later lost reliable connectivity between London Area Control and the NAS, forcing fallback procedures and nationwide flow restrictions.
More than 2,000 flights were delayed, cancelled or diverted. NATS handled about 1,800 fewer flights than planned that day. The agency said the event was unrelated to the 2023 flight-planning outage and a July 2025 radar issue, and that there is no evidence of military error, cyber attack or malicious activity at this stage of the inquiry.
Timeline details in the preliminary findings show the first brief LAC–NAS disconnect at 10:02, a recovery after roughly 45 seconds with no immediate operational impact, then repeated drops from 12:32 as corrupted data overwhelmed processing. Restrictions began around 12:45. By 13:32 the link had failed completely and some sectors were limited to as few as 30 aircraft per hour, with arrival caps that stranded outbound flights at foreign airports waiting for UK slots.
Engineers started a controlled NAS restart at 15:17 and completed it at 16:09, then spent hours reconciling duplicate flight plans and callsign associations until systems stabilized around 18:50. Remaining restrictions lifted at 19:30. UK departure stoppages totaled about four and a half hours across a six-hour window. Industry coordination calls continued through 11 September as airlines rebuilt schedules and positioning flights.
NATS says a software fix from its supplier is already in testing and safety assurance, with interim monitoring and escalation rules around LAC–NAS link failures while that patch is validated. A full Major Incident Investigation is due within 60 days of 8 September. That deeper review will examine resilience, command structure, communications with airlines, airports and EUROCONTROL, software defect history and whether recommendations from earlier incidents were fully effective. The Civil Aviation Authority is running a separate government-requested review of service resilience.
The striking engineering detail is how narrow the failure mode was: the vulnerable code path was only open for about a millisecond. A second request arriving even slightly earlier or later would have allowed the first update to finish cleanly. That precision helps explain why the defect stayed hidden until this sequence occurred during a busy Monday operation involving routine squawk reassignment traffic.
Safety margins were maintained throughout, NATS said—controllers kept radio and radar contact and used standard fallback separation. The operational cost was capacity and connectivity, not mid-air conflict. Ground congestion built because arrivals continued while departures were stopped, forcing diversion procedures for some inbound aircraft already airborne.
For airlines and passengers, the episode is a reminder that modern ATC still depends on aging software modules where tiny timing races can cascade into national disruption. The preliminary findings may still change as the 60-day investigation completes, but the core claim is already clear: a one-millisecond legacy defect, not a new cyber threat, knocked thousands of UK flights off schedule.
Sources: NATS preliminary investigation via UK Aviation News; FlightGlobal.















Comments
Loading comments…