Imagine you bought a smart lock for your front door — except the manufacturer left the default password printed on the box, the firmware update channel has no authentication, and anyone with a $200 radio can send it commands. Now imagine that door is orbiting Earth at 7.8 km/s, and you cannot physically reach it to swap the lock. That is the state of commercial off-the-shelf (COTS) communication modules in small satellites today. The committed claim: this is the first in-depth security evaluation of widely deployed COTS COM modules used in small satellites, and the vulnerabilities found are not theoretical — at least 28 missions currently in orbit are susceptible to hostile takeover. The paper constructs a tailored threat taxonomy for attacks targeting the Communication Subsystem (COM), then systematically analyzes representative COM systems from multiple vendors. The results are grim across every layer: firmware, protocols, and architectural design all show severe weaknesses. The COM subsystem is the front door of every satellite. It is continuously exposed by design — it must listen for commands from the ground — and it is implicitly trusted as the entry point for command and control. The modular COTS approach that has made small satellites affordable (launch costs dropping from $50,000/kg to under $3,000/kg in a decade) has also imported the entire supply-chain security problem from consumer electronics into orbit. The difference is that you cannot recall a satellite for a hardware patch. The attack surface is permanently deployed. Where does this sit on the ladder? There is prior work on satellite security — notably Willbold et al.'s 2023 'Space Odyssey' study at USENIX Security, which examined satellite firmware generally, and Pavur et al.'s work on VSAT traffic interception. But those studies either focused on higher-layer protocols or on specific mission architectures. SatBleed is the first to systematically target the COM module layer specifically — the COTS radio hardware that multiple vendors sell and dozens of missions share. The novelty is in the combination of vendor-level analysis, vulnerability identification, and correlation with open-source telemetry data to confirm real in-orbit exposure. The IEEE S&P 2026 acceptance signals the community considers this a genuine contribution. The integrity picture is mixed in useful ways. The authors correlate their findings against open-source telemetry data (SatNOGS and similar), which provides a partially independent validation channel — they are not just claiming theoretical vulnerabilities but identifying specific missions that use the affected modules. However, responsible disclosure constraints likely limit what can be shown publicly, and the 28-mission count is described as a lower bound inferred from open data, not confirmed through direct exploitation. No pre-registration, but the threat taxonomy provides a structured framework that makes cherry-picking harder. The milestone question for this subfield is not about a single number but about an adoption threshold: when do satellite manufacturers treat COM module security the way the automotive industry now treats CAN bus security — as a mandatory design constraint rather than an afterthought? The automotive analogy is precise: the CAN bus was designed for trusted environments, got connected to the internet via telematics modules, and the industry spent a decade catching up after Miller and Valasek's 2015 Jeep hack. Satellites are at the 'pre-Jeep-hack' stage. The next milestone is a mandated security certification standard for COTS COM modules, which is probably 3-5 years out if this paper and its successors generate sufficient pressure. The obvious experiment not run: active exploitation of a live satellite, even a cooperative test target. The authors almost certainly did not attempt this because (a) it would be illegal without explicit mission-owner cooperation, (b) the responsible-disclosure and ethics-board constraints at IEEE S&P would prohibit it, and (c) the reputational and legal risk is enormous. This is the right call — but it means the '28 vulnerable missions' claim rests on architectural inference rather than demonstrated compromise. A coordinated red-team exercise with a willing satellite operator would be the definitive next step.