{"schema_version":1,"title":"Zephyr Project Zephyr OS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in Zephyr Project Zephyr OS: 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13216, was published on 25 August 2026.","url":"https://junglewise.ai/threats/technologies/zephyr-os","json_url":"https://junglewise.ai/threats/technologies/zephyr-os.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/zephyr-os","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":25,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":25},"latest":[{"cve":"CVE-2026-13216","cvss":6.1,"epss":0.0018,"slug":"cve-2026-13216-zephyr-virtio-pci-driver-stack-buffer-overflow-in-capability","title":"Zephyr virtio PCI driver stack buffer overflow in capability parsing","severity":"medium","exploited":false,"published_at":"2026-08-25T17:17:04.993+00:00","url":"https://junglewise.ai/threats/cve-2026-13216-zephyr-virtio-pci-driver-stack-buffer-overflow-in-capability"},{"cve":"CVE-2026-12364","cvss":8.4,"epss":0.0016,"slug":"cve-2026-12364-zephyr-os-logging-system-call-validation-bypass","title":"Zephyr OS logging system-call validation bypass","severity":"high","exploited":false,"published_at":"2026-08-14T18:17:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-12364-zephyr-os-logging-system-call-validation-bypass"},{"cve":"CVE-2026-10683","cvss":2.4,"slug":"cve-2026-10683-zephyr-os-synopsys-designware-i2c-driver-denial-of-service","title":"Zephyr OS Synopsys DesignWare I2C driver denial of service","severity":"low","exploited":false,"published_at":"2026-07-27T19:17:14.683+00:00","url":"https://junglewise.ai/threats/cve-2026-10683-zephyr-os-synopsys-designware-i2c-driver-denial-of-service"},{"cve":"CVE-2026-10679","cvss":3.3,"slug":"cve-2026-10679-zephyr-os-divide-by-zero-in-designware-spi-driver","title":"Zephyr OS divide by zero in DesignWare SPI driver","severity":"low","exploited":false,"published_at":"2026-07-21T22:17:00.177+00:00","url":"https://junglewise.ai/threats/cve-2026-10679-zephyr-os-divide-by-zero-in-designware-spi-driver"},{"cve":"CVE-2026-10677","cvss":6.5,"slug":"cve-2026-10677-zephyr-os-kernel-heap-memory-leak-in-z-vrfy-k-poll","title":"Zephyr OS kernel heap memory leak in z_vrfy_k_poll","severity":"medium","exploited":false,"published_at":"2026-07-21T22:16:59.923+00:00","url":"https://junglewise.ai/threats/cve-2026-10677-zephyr-os-kernel-heap-memory-leak-in-z-vrfy-k-poll"},{"cve":"CVE-2026-10668","cvss":2.4,"slug":"cve-2026-10668-zephyr-os-nuvoton-numaker-hsusbd-denial-of-service-in-usb-driver","title":"Zephyr OS Nuvoton NuMaker HSUSBD denial of service in USB driver","severity":"low","exploited":false,"published_at":"2026-07-12T17:16:24.787+00:00","url":"https://junglewise.ai/threats/cve-2026-10668-zephyr-os-nuvoton-numaker-hsusbd-denial-of-service-in-usb-driver"},{"cve":"CVE-2026-10666","cvss":8.1,"slug":"cve-2026-10666-zephyr-os-stack-overflow-in-ipv4-and-ipv6-address-parsing","title":"Zephyr OS stack overflow in IPv4 and IPv6 address parsing","severity":"high","exploited":false,"published_at":"2026-07-12T17:16:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-10666-zephyr-os-stack-overflow-in-ipv4-and-ipv6-address-parsing"},{"cve":"CVE-2026-10660","cvss":6.4,"slug":"cve-2026-10660-zephyr-os-bluetooth-bap-broadcast-assistant-out-of-bounds-write","title":"Zephyr OS Bluetooth BAP Broadcast Assistant out-of-bounds write","severity":"medium","exploited":false,"published_at":"2026-07-11T17:16:23.92+00:00","url":"https://junglewise.ai/threats/cve-2026-10660-zephyr-os-bluetooth-bap-broadcast-assistant-out-of-bounds-write"},{"cve":"CVE-2026-10657","cvss":3.7,"slug":"cve-2026-10657-zephyr-os-out-of-bounds-read-in-dns-resolver-mdns-check","title":"Zephyr OS out-of-bounds read in DNS resolver mDNS check","severity":"low","exploited":false,"published_at":"2026-07-05T23:16:52.863+00:00","url":"https://junglewise.ai/threats/cve-2026-10657-zephyr-os-out-of-bounds-read-in-dns-resolver-mdns-check"},{"cve":"CVE-2026-8023","cvss":7.5,"slug":"cve-2026-8023-zephyr-rtos-path-traversal-in-http-server-static-filesystem","title":"Zephyr RTOS path traversal in HTTP server static-filesystem handler","severity":"high","exploited":false,"published_at":"2026-06-29T23:16:43.777+00:00","url":"https://junglewise.ai/threats/cve-2026-8023-zephyr-rtos-path-traversal-in-http-server-static-filesystem"},{"cve":"CVE-2026-10648","cvss":6.2,"slug":"cve-2026-10648-zephyr-os-null-pointer-dereference-in-mcumgr-serial-transport","title":"Zephyr OS NULL pointer dereference in MCUmgr serial transport","severity":"medium","exploited":false,"published_at":"2026-06-29T23:16:42.18+00:00","url":"https://junglewise.ai/threats/cve-2026-10648-zephyr-os-null-pointer-dereference-in-mcumgr-serial-transport"},{"cve":"CVE-2026-10658","cvss":7.1,"slug":"cve-2026-10658-zephyr-os-denial-of-service-in-bluetooth-host-iso-receive-path","title":"Zephyr OS denial of service in Bluetooth Host ISO receive path","severity":"high","exploited":false,"published_at":"2026-06-23T01:16:26.867+00:00","url":"https://junglewise.ai/threats/cve-2026-10658-zephyr-os-denial-of-service-in-bluetooth-host-iso-receive-path"},{"cve":"CVE-2026-10645","cvss":4.9,"slug":"cve-2026-10645-zephyr-os-out-of-bounds-read-in-ext2-directory-entry-parser","title":"Zephyr OS out-of-bounds read in ext2 directory-entry parser","severity":"medium","exploited":false,"published_at":"2026-06-23T01:16:26.607+00:00","url":"https://junglewise.ai/threats/cve-2026-10645-zephyr-os-out-of-bounds-read-in-ext2-directory-entry-parser"},{"cve":"CVE-2026-10687","cvss":0,"slug":"cve-2026-10687-zephyr-os-withdrawn-vulnerability-in-unreleased-development-code","title":"Zephyr OS withdrawn vulnerability in unreleased development code","severity":"info","exploited":false,"published_at":"2026-06-18T17:16:27.523+00:00","url":"https://junglewise.ai/threats/cve-2026-10687-zephyr-os-withdrawn-vulnerability-in-unreleased-development-code"},{"cve":"CVE-2026-10639","cvss":4.8,"slug":"cve-2026-10639-zephyr-os-use-after-free-in-icmpv4-echo-request-handler","title":"Zephyr OS use-after-free in ICMPv4 echo request handler","severity":"medium","exploited":false,"published_at":"2026-06-16T15:16:34.207+00:00","url":"https://junglewise.ai/threats/cve-2026-10639-zephyr-os-use-after-free-in-icmpv4-echo-request-handler"},{"cve":"CVE-2026-10637","cvss":5.9,"slug":"cve-2026-10637-zephyr-os-use-after-free-in-ipv6-mld-send-path","title":"Zephyr OS use-after-free in IPv6 MLD send path","severity":"medium","exploited":false,"published_at":"2026-06-16T15:16:33.987+00:00","url":"https://junglewise.ai/threats/cve-2026-10637-zephyr-os-use-after-free-in-ipv6-mld-send-path"},{"cve":"CVE-2026-10636","cvss":3.7,"slug":"cve-2026-10636-zephyr-os-use-after-free-in-ipv4-igmp-implementation","title":"Zephyr OS use-after-free in IPv4 IGMP implementation","severity":"low","exploited":false,"published_at":"2026-06-16T15:16:33.867+00:00","url":"https://junglewise.ai/threats/cve-2026-10636-zephyr-os-use-after-free-in-ipv4-igmp-implementation"},{"cve":"CVE-2026-10635","cvss":6.3,"slug":"cve-2026-10635-zephyr-os-use-after-free-in-xtensa-mmu-page-table-management","title":"Zephyr OS use-after-free in Xtensa MMU page-table management","severity":"medium","exploited":false,"published_at":"2026-06-16T06:16:57.77+00:00","url":"https://junglewise.ai/threats/cve-2026-10635-zephyr-os-use-after-free-in-xtensa-mmu-page-table-management"},{"cve":"CVE-2026-10676","cvss":0,"slug":"cve-2026-10676-zephyr-os-unreachable-defect-in-unreleased-development-code","title":"Zephyr OS unreachable defect in unreleased development code","severity":"info","exploited":false,"published_at":"2026-06-12T00:16:18.86+00:00","url":"https://junglewise.ai/threats/cve-2026-10676-zephyr-os-unreachable-defect-in-unreleased-development-code"},{"cve":"CVE-2026-5068","cvss":7.6,"slug":"cve-2026-5068-zephyr-os-out-of-bounds-write-in-bluetooth-l2cap-le-coc","title":"Zephyr OS out-of-bounds write in Bluetooth L2CAP LE CoC","severity":"high","exploited":false,"published_at":"2026-06-09T08:16:29.073+00:00","url":"https://junglewise.ai/threats/cve-2026-5068-zephyr-os-out-of-bounds-write-in-bluetooth-l2cap-le-coc"},{"cve":"CVE-2026-5589","cvss":8.8,"slug":"cve-2026-5589-zephyr-rtos-integer-underflow-in-bluetooth-mesh-solicitation","title":"Zephyr RTOS integer underflow in Bluetooth Mesh solicitation handling","severity":"info","exploited":false,"published_at":"2026-06-04T20:16:58.54+00:00","url":"https://junglewise.ai/threats/cve-2026-5589-zephyr-rtos-integer-underflow-in-bluetooth-mesh-solicitation"},{"cve":"CVE-2026-5071","cvss":6.1,"slug":"cve-2026-5071-zephyr-rtos-out-of-bounds-read-in-socketcan-zcan-sendto-ctx","title":"Zephyr RTOS out-of-bounds read in SocketCAN zcan_sendto_ctx","severity":"medium","exploited":false,"published_at":"2026-05-30T08:16:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-5071-zephyr-rtos-out-of-bounds-read-in-socketcan-zcan-sendto-ctx"},{"cve":"CVE-2026-5072","cvss":6.5,"slug":"cve-2026-5072-zephyr-rtos-bitwise-shift-vulnerability-in-ptp-subsystem","title":"Zephyr RTOS bitwise shift vulnerability in PTP subsystem","severity":"info","exploited":false,"published_at":"2026-05-22T08:16:15.027+00:00","url":"https://junglewise.ai/threats/cve-2026-5072-zephyr-rtos-bitwise-shift-vulnerability-in-ptp-subsystem"},{"cve":"CVE-2026-1681","cvss":6.1,"epss":0.0011,"slug":"cve-2026-1681-zephyr-rtos-stack-overflow-via-icmp-ping-to-self-in-net-shell","title":"Zephyr RTOS stack overflow via ICMP ping to self in net shell","severity":"medium","exploited":false,"published_at":"2026-05-12T07:16:09.843+00:00","url":"https://junglewise.ai/threats/cve-2026-1681-zephyr-rtos-stack-overflow-via-icmp-ping-to-self-in-net-shell"},{"cve":"CVE-2026-5590","cvss":6.4,"epss":0.0016,"slug":"cve-2026-5590-zephyr-rtos-null-pointer-dereference-in-tcp-stack","title":"Zephyr RTOS NULL pointer dereference in TCP stack","severity":"medium","exploited":false,"published_at":"2026-04-05T04:16:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-5590-zephyr-rtos-null-pointer-dereference-in-tcp-stack"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Zephyr Project Zephyr","slug":"zephyr","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/zephyr"}],"technology":{"hub":true,"name":"Zephyr Project Zephyr OS","slug":"zephyr-os","vendor":{"name":"Zephyr Project","slug":"zephyr-project","url":"https://junglewise.ai/threats/vendors/zephyr-project"},"aliases":[],"category":"operating-system","homepage":"https://zephyrproject.org/","repo_url":"https://github.com/zephyrproject-rtos/zephyr","description":"A small, scalable real-time operating system (RTOS) optimized for resource-constrained devices.","url":"https://junglewise.ai/threats/technologies/zephyr-os"},"most_severe":[{"cve":"CVE-2026-12364","cvss":8.4,"epss":0.0016,"slug":"cve-2026-12364-zephyr-os-logging-system-call-validation-bypass","title":"Zephyr OS logging system-call validation bypass","severity":"high","exploited":false,"published_at":"2026-08-14T18:17:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-12364-zephyr-os-logging-system-call-validation-bypass"},{"cve":"CVE-2026-10666","cvss":8.1,"slug":"cve-2026-10666-zephyr-os-stack-overflow-in-ipv4-and-ipv6-address-parsing","title":"Zephyr OS stack overflow in IPv4 and IPv6 address parsing","severity":"high","exploited":false,"published_at":"2026-07-12T17:16:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-10666-zephyr-os-stack-overflow-in-ipv4-and-ipv6-address-parsing"},{"cve":"CVE-2026-5068","cvss":7.6,"slug":"cve-2026-5068-zephyr-os-out-of-bounds-write-in-bluetooth-l2cap-le-coc","title":"Zephyr OS out-of-bounds write in Bluetooth L2CAP LE CoC","severity":"high","exploited":false,"published_at":"2026-06-09T08:16:29.073+00:00","url":"https://junglewise.ai/threats/cve-2026-5068-zephyr-os-out-of-bounds-write-in-bluetooth-l2cap-le-coc"},{"cve":"CVE-2026-8023","cvss":7.5,"slug":"cve-2026-8023-zephyr-rtos-path-traversal-in-http-server-static-filesystem","title":"Zephyr RTOS path traversal in HTTP server static-filesystem handler","severity":"high","exploited":false,"published_at":"2026-06-29T23:16:43.777+00:00","url":"https://junglewise.ai/threats/cve-2026-8023-zephyr-rtos-path-traversal-in-http-server-static-filesystem"},{"cve":"CVE-2026-10658","cvss":7.1,"slug":"cve-2026-10658-zephyr-os-denial-of-service-in-bluetooth-host-iso-receive-path","title":"Zephyr OS denial of service in Bluetooth Host ISO receive path","severity":"high","exploited":false,"published_at":"2026-06-23T01:16:26.867+00:00","url":"https://junglewise.ai/threats/cve-2026-10658-zephyr-os-denial-of-service-in-bluetooth-host-iso-receive-path"},{"cve":"CVE-2026-10677","cvss":6.5,"slug":"cve-2026-10677-zephyr-os-kernel-heap-memory-leak-in-z-vrfy-k-poll","title":"Zephyr OS kernel heap memory leak in z_vrfy_k_poll","severity":"medium","exploited":false,"published_at":"2026-07-21T22:16:59.923+00:00","url":"https://junglewise.ai/threats/cve-2026-10677-zephyr-os-kernel-heap-memory-leak-in-z-vrfy-k-poll"},{"cve":"CVE-2026-5590","cvss":6.4,"epss":0.0016,"slug":"cve-2026-5590-zephyr-rtos-null-pointer-dereference-in-tcp-stack","title":"Zephyr RTOS NULL pointer dereference in TCP stack","severity":"medium","exploited":false,"published_at":"2026-04-05T04:16:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-5590-zephyr-rtos-null-pointer-dereference-in-tcp-stack"},{"cve":"CVE-2026-10660","cvss":6.4,"slug":"cve-2026-10660-zephyr-os-bluetooth-bap-broadcast-assistant-out-of-bounds-write","title":"Zephyr OS Bluetooth BAP Broadcast Assistant out-of-bounds write","severity":"medium","exploited":false,"published_at":"2026-07-11T17:16:23.92+00:00","url":"https://junglewise.ai/threats/cve-2026-10660-zephyr-os-bluetooth-bap-broadcast-assistant-out-of-bounds-write"},{"cve":"CVE-2026-10635","cvss":6.3,"slug":"cve-2026-10635-zephyr-os-use-after-free-in-xtensa-mmu-page-table-management","title":"Zephyr OS use-after-free in Xtensa MMU page-table management","severity":"medium","exploited":false,"published_at":"2026-06-16T06:16:57.77+00:00","url":"https://junglewise.ai/threats/cve-2026-10635-zephyr-os-use-after-free-in-xtensa-mmu-page-table-management"},{"cve":"CVE-2026-10648","cvss":6.2,"slug":"cve-2026-10648-zephyr-os-null-pointer-dereference-in-mcumgr-serial-transport","title":"Zephyr OS NULL pointer dereference in MCUmgr serial transport","severity":"medium","exploited":false,"published_at":"2026-06-29T23:16:42.18+00:00","url":"https://junglewise.ai/threats/cve-2026-10648-zephyr-os-null-pointer-dereference-in-mcumgr-serial-transport"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}