Technology · Zephyr Project
Zephyr Project Zephyr vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 70 vulnerabilities in Zephyr Project Zephyr: 0 in the last 7 days and 53 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-16514, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 53
- Critical, all time
- 2
- Exploited in the wild
- 0
About Zephyr Project Zephyr
Zephyr is a small, scalable real-time operating system (RTOS) optimized for resource-constrained devices across multiple architectures.
Latest Zephyr Project Zephyr vulnerabilities
- CVE-2026-16514: Zephyr RTOS gPTP out-of-bounds read in Announce message handlingmediumCVSS 4.3EPSS 0.2%
- CVE-2026-16512: Zephyr RTOS gPTP message header out-of-bounds readlowCVSS 3.1EPSS 0.2%
- CVE-2026-15893: Zephyr RTOS IPv6 reachable time calculation denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-15891: Zephyr MQTT-SN client NULL pointer dereference in keepalive handlerhighCVSS 7.5EPSS 0.3%
- CVE-2026-14697: Zephyr RTOS IPv6 Neighbor Solicitation packet leak denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-14696: Zephyr RTOS Ethernet bridge packet leak denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-13735: Zephyr WireGuard authentication bypass in keepalive handlinglowCVSS 3.7EPSS 0.3%
- CVE-2026-13734: Zephyr WireGuard replay validation bypass in data-plane handlermediumCVSS 6.5EPSS 0.3%
- CVE-2026-13481: Zephyr RTOS PTP management-message parser out-of-bounds read in tlv.cmediumCVSS 5.4EPSS 0.3%
- CVE-2026-13480: Zephyr LoRaWAN TS004 buffer over-read in frag_transport_package_callbacklowCVSS 3.1EPSS 0.3%
- CVE-2026-13479: Zephyr RTOS LoRaWAN clock-sync buffer over-readlowCVSS 3.1EPSS 0.2%
- CVE-2026-13215: Zephyr ext2 filesystem driver superblock validation bypassmediumCVSS 6.8EPSS 0.2%
- CVE-2026-13214: Zephyr OCPP client stack buffer overflow in GetConfiguration handlercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-9728: Zephyr mailbox TOCTOU race in syscall verifiermediumCVSS 6.4EPSS 0.1%
- CVE-2026-9771: Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointershighCVSS 8.8EPSS 0.1%
- CVE-2026-12366: Zephyr use-after-free in dynamic k_timer cleanuphighCVSS 8.8EPSS 0.2%
- CVE-2026-12365: Zephyr work queue use-after-free in timeout handlingmediumCVSS 5.8EPSS 0.1%
- CVE-2026-12234: Zephyr TOCTOU in userspace syscall verifiers sendmsg/recvmsghighCVSS 7.8EPSS 0.1%
- CVE-2026-12233: Zephyr PSA Protected Storage uninitialized mutex denial of servicemediumCVSS 5.9EPSS 0.5%
- CVE-2026-12232: Intel ALH digital-audio-interface driver information disclosuremediumCVSS 6.1EPSS 0.1%
- CVE-2026-12051: Zephyr USB DFU NULL pointer dereference in handle_downloadmediumCVSS 4.6EPSS 0.2%
- CVE-2026-8718: Zephyr DTLS Connection ID buffer overflow in getsockopthighCVSS 8.4EPSS 0.2%
- CVE-2026-11811: Zephyr RTOS UpdateHub socket descriptor leak in CoAP/DTLS setuplowCVSS 3.7EPSS 0.4%
- CVE-2026-10774: Zephyr Bluetooth Mesh PSA key slot leak on subnet teardownlowCVSS 2.4EPSS 0.3%
- CVE-2026-10686: Zephyr RTOS infinite loop in IPv6 forwarding pathmediumCVSS 5.8
Most severe Zephyr Project Zephyr vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-13214: Zephyr OCPP client stack buffer overflow in GetConfiguration handlercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-5067: Zephyr RTOS stack overflow in HTTP server WebSocket upgradecriticalCVSS 9.8
- CVE-2026-12366: Zephyr use-after-free in dynamic k_timer cleanuphighCVSS 8.8EPSS 0.2%
- CVE-2026-9771: Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointershighCVSS 8.8EPSS 0.1%
- CVE-2026-10643: Zephyr RTOS heap overflow in IP socket recvmsg implementationhighCVSS 8.7
- CVE-2026-8718: Zephyr DTLS Connection ID buffer overflow in getsockopthighCVSS 8.4EPSS 0.2%
- CVE-2026-10673: Zephyr ADIN2111/ADIN1110 Ethernet driver out-of-bounds writehighCVSS 8.3
- CVE-2026-10672: Zephyr RTOS out-of-bounds read in LwM2M firmware pull URI handlinghighCVSS 8.2
- CVE-2026-10678: Zephyr RTOS NULL pointer dereference and OOB write in MCTP I2C+GPIOhighCVSS 8.1
- CVE-2026-7656: Zephyr RTOS IPv6 Neighbor Discovery validation bypasshighCVSS 8.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 9 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 6 | 0 | |
| 27 Jul 2026 | 5 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 8 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 8 | 1 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 3 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/zephyr.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Zephyr Project Zephyr vulnerabilities", https://junglewise.ai/threats/technologies/zephyr, 26 September 2026.