I agree C is not a generally safe language, but it can be done correctly. I'm not surprised that many cubesat satellite projects have failed due to software problems. Whatever language is chosen, these are still generally launched by students or those learning the ropes. Failure should be expected and using a very strict language will help, but is ultimately only a crutch. It comes with a lot of cognitive trade offs.
Not having an update mechanism period though? That's positively madness. Not having a fallback system in the event of systemic failure? Unheard of in real satellite systems. Bad things happen. Ada will not protect you against all classes of failure and will incur a very large development cost.
What happens in the real world? C. Even some mixed assembly and in the worst of worlds Java. What do I want to see? More Rust. Rust covers the worst of errors without much cognitive overhead, and zero runtime overhead. It's bare metal and very efficient. It's been in space and I guarantee more of it will be going to space.