{"schema_version":1,"title":"Zephyr Project Zephyr vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 72 vulnerabilities in Zephyr Project Zephyr: 2 in the last 7 days and 55 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15890, was published on 21 September 2026.","url":"https://junglewise.ai/threats/technologies/zephyr","json_url":"https://junglewise.ai/threats/technologies/zephyr.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/zephyr","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":20,"all_time":72,"critical":2,"exploited":0,"last_7_days":2,"last_30_days":10,"last_90_days":55,"last_365_days":72},"latest":[{"cve":"CVE-2026-15890","cvss":5.3,"epss":0.0006,"slug":"cve-2026-15890-the-default-aead-nonce-provider-for-the-psa-internal-trusted","title":"Zephyr PSA Trusted Storage AEAD nonce reuse in concurrent writes","severity":"medium","exploited":false,"published_at":"2026-09-21T22:16:56.143+00:00","url":"https://junglewise.ai/threats/cve-2026-15890-the-default-aead-nonce-provider-for-the-psa-internal-trusted"},{"cve":"CVE-2026-17050","cvss":5.7,"epss":0.0016,"slug":"cve-2026-17050-the-experimental-usb-host-stack-allocates-a-per-device","title":"Zephyr RTOS USB host stack double-free in configuration descriptor","severity":"medium","exploited":false,"published_at":"2026-09-21T17:17:34.02+00:00","url":"https://junglewise.ai/threats/cve-2026-17050-the-experimental-usb-host-stack-allocates-a-per-device"},{"cve":"CVE-2026-16514","cvss":4.3,"epss":0.0024,"slug":"cve-2026-16514-zephyr-rtos-gptp-out-of-bounds-read-in-announce-message-handling","title":"Zephyr RTOS gPTP out-of-bounds read in Announce message handling","severity":"medium","exploited":false,"published_at":"2026-09-18T15:17:05.753+00:00","url":"https://junglewise.ai/threats/cve-2026-16514-zephyr-rtos-gptp-out-of-bounds-read-in-announce-message-handling"},{"cve":"CVE-2026-16512","cvss":3.1,"epss":0.0017,"slug":"cve-2026-16512-zephyr-rtos-gptp-message-header-out-of-bounds-read","title":"Zephyr RTOS gPTP message header out-of-bounds read","severity":"low","exploited":false,"published_at":"2026-09-18T15:17:05.603+00:00","url":"https://junglewise.ai/threats/cve-2026-16512-zephyr-rtos-gptp-message-header-out-of-bounds-read"},{"cve":"CVE-2026-15893","cvss":6.5,"epss":0.002,"slug":"cve-2026-15893-zephyr-rtos-ipv6-reachable-time-calculation-denial-of-service","title":"Zephyr RTOS IPv6 reachable time calculation denial of service","severity":"medium","exploited":false,"published_at":"2026-09-14T19:17:14.627+00:00","url":"https://junglewise.ai/threats/cve-2026-15893-zephyr-rtos-ipv6-reachable-time-calculation-denial-of-service"},{"cve":"CVE-2026-15891","cvss":7.5,"epss":0.0034,"slug":"cve-2026-15891-zephyr-mqtt-sn-client-null-pointer-dereference-in-keepalive","title":"Zephyr MQTT-SN client NULL pointer dereference in keepalive handler","severity":"high","exploited":false,"published_at":"2026-09-13T23:16:27.87+00:00","url":"https://junglewise.ai/threats/cve-2026-15891-zephyr-mqtt-sn-client-null-pointer-dereference-in-keepalive"},{"cve":"CVE-2026-14697","cvss":6.5,"epss":0.0018,"slug":"cve-2026-14697-zephyr-rtos-ipv6-neighbor-solicitation-packet-leak-denial-of","title":"Zephyr RTOS IPv6 Neighbor Solicitation packet leak denial of service","severity":"medium","exploited":false,"published_at":"2026-08-31T20:17:03.253+00:00","url":"https://junglewise.ai/threats/cve-2026-14697-zephyr-rtos-ipv6-neighbor-solicitation-packet-leak-denial-of"},{"cve":"CVE-2026-14696","cvss":6.5,"epss":0.002,"slug":"cve-2026-14696-zephyr-rtos-ethernet-bridge-packet-leak-denial-of-service","title":"Zephyr RTOS Ethernet bridge packet leak denial of service","severity":"medium","exploited":false,"published_at":"2026-08-31T19:16:46.14+00:00","url":"https://junglewise.ai/threats/cve-2026-14696-zephyr-rtos-ethernet-bridge-packet-leak-denial-of-service"},{"cve":"CVE-2026-13735","cvss":3.7,"epss":0.0025,"slug":"cve-2026-13735-zephyr-wireguard-authentication-bypass-in-keepalive-handling","title":"Zephyr WireGuard authentication bypass in keepalive handling","severity":"low","exploited":false,"published_at":"2026-08-28T22:16:46.187+00:00","url":"https://junglewise.ai/threats/cve-2026-13735-zephyr-wireguard-authentication-bypass-in-keepalive-handling"},{"cve":"CVE-2026-13734","cvss":6.5,"epss":0.0025,"slug":"cve-2026-13734-zephyr-wireguard-replay-validation-bypass-in-data-plane-handler","title":"Zephyr WireGuard replay validation bypass in data-plane handler","severity":"medium","exploited":false,"published_at":"2026-08-28T22:16:46.057+00:00","url":"https://junglewise.ai/threats/cve-2026-13734-zephyr-wireguard-replay-validation-bypass-in-data-plane-handler"},{"cve":"CVE-2026-13481","cvss":5.4,"epss":0.0026,"slug":"cve-2026-13481-zephyr-rtos-ptp-management-message-parser-out-of-bounds-read-in","title":"Zephyr RTOS PTP management-message parser out-of-bounds read in tlv.c","severity":"medium","exploited":false,"published_at":"2026-08-26T15:16:42.953+00:00","url":"https://junglewise.ai/threats/cve-2026-13481-zephyr-rtos-ptp-management-message-parser-out-of-bounds-read-in"},{"cve":"CVE-2026-13480","cvss":3.1,"epss":0.0026,"slug":"cve-2026-13480-zephyr-lorawan-ts004-buffer-over-read-in-frag-transport-package","title":"Zephyr LoRaWAN TS004 buffer over-read in frag_transport_package_callback","severity":"low","exploited":false,"published_at":"2026-08-26T15:16:42.83+00:00","url":"https://junglewise.ai/threats/cve-2026-13480-zephyr-lorawan-ts004-buffer-over-read-in-frag-transport-package"},{"cve":"CVE-2026-13479","cvss":3.1,"epss":0.0024,"slug":"cve-2026-13479-zephyr-rtos-lorawan-clock-sync-buffer-over-read","title":"Zephyr RTOS LoRaWAN clock-sync buffer over-read","severity":"low","exploited":false,"published_at":"2026-08-26T15:16:42.693+00:00","url":"https://junglewise.ai/threats/cve-2026-13479-zephyr-rtos-lorawan-clock-sync-buffer-over-read"},{"cve":"CVE-2026-13215","cvss":6.8,"epss":0.0018,"slug":"cve-2026-13215-zephyr-ext2-filesystem-driver-superblock-validation-bypass","title":"Zephyr ext2 filesystem driver superblock validation bypass","severity":"medium","exploited":false,"published_at":"2026-08-25T05:17:20.187+00:00","url":"https://junglewise.ai/threats/cve-2026-13215-zephyr-ext2-filesystem-driver-superblock-validation-bypass"},{"cve":"CVE-2026-13214","cvss":9.8,"epss":0.0051,"slug":"cve-2026-13214-zephyr-ocpp-client-stack-buffer-overflow-in-getconfiguration","title":"Zephyr OCPP client stack buffer overflow in GetConfiguration handler","severity":"critical","exploited":false,"published_at":"2026-08-25T05:17:20.06+00:00","url":"https://junglewise.ai/threats/cve-2026-13214-zephyr-ocpp-client-stack-buffer-overflow-in-getconfiguration"},{"cve":"CVE-2026-9728","cvss":6.4,"epss":0.0011,"slug":"cve-2026-9728-zephyr-mailbox-toctou-race-in-syscall-verifier","title":"Zephyr mailbox TOCTOU race in syscall verifier","severity":"medium","exploited":false,"published_at":"2026-08-24T15:16:49.01+00:00","url":"https://junglewise.ai/threats/cve-2026-9728-zephyr-mailbox-toctou-race-in-syscall-verifier"},{"cve":"CVE-2026-9771","cvss":8.8,"epss":0.0014,"slug":"cve-2026-9771-zephyr-rtos-flash-copy-privilege-escalation-via-unvalidated-device","title":"Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointers","severity":"high","exploited":false,"published_at":"2026-08-17T17:16:57.72+00:00","url":"https://junglewise.ai/threats/cve-2026-9771-zephyr-rtos-flash-copy-privilege-escalation-via-unvalidated-device"},{"cve":"CVE-2026-12366","cvss":8.8,"epss":0.0017,"slug":"cve-2026-12366-zephyr-use-after-free-in-dynamic-k-timer-cleanup","title":"Zephyr use-after-free in dynamic k_timer cleanup","severity":"high","exploited":false,"published_at":"2026-08-14T18:17:22.043+00:00","url":"https://junglewise.ai/threats/cve-2026-12366-zephyr-use-after-free-in-dynamic-k-timer-cleanup"},{"cve":"CVE-2026-12365","cvss":5.8,"epss":0.0013,"slug":"cve-2026-12365-zephyr-work-queue-use-after-free-in-timeout-handling","title":"Zephyr work queue use-after-free in timeout handling","severity":"medium","exploited":false,"published_at":"2026-08-14T18:17:21.933+00:00","url":"https://junglewise.ai/threats/cve-2026-12365-zephyr-work-queue-use-after-free-in-timeout-handling"},{"cve":"CVE-2026-12234","cvss":7.8,"epss":0.0011,"slug":"cve-2026-12234-zephyr-toctou-in-userspace-syscall-verifiers-sendmsg-recvmsg","title":"Zephyr TOCTOU in userspace syscall verifiers sendmsg/recvmsg","severity":"high","exploited":false,"published_at":"2026-08-12T05:17:42.143+00:00","url":"https://junglewise.ai/threats/cve-2026-12234-zephyr-toctou-in-userspace-syscall-verifiers-sendmsg-recvmsg"},{"cve":"CVE-2026-12233","cvss":5.9,"epss":0.0051,"slug":"cve-2026-12233-zephyr-psa-protected-storage-uninitialized-mutex-denial-of","title":"Zephyr PSA Protected Storage uninitialized mutex denial of service","severity":"medium","exploited":false,"published_at":"2026-08-12T05:17:42.01+00:00","url":"https://junglewise.ai/threats/cve-2026-12233-zephyr-psa-protected-storage-uninitialized-mutex-denial-of"},{"cve":"CVE-2026-12232","cvss":6.1,"epss":0.0015,"slug":"cve-2026-12232-intel-alh-digital-audio-interface-driver-information-disclosure","title":"Intel ALH digital-audio-interface driver information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-12T05:17:41.86+00:00","url":"https://junglewise.ai/threats/cve-2026-12232-intel-alh-digital-audio-interface-driver-information-disclosure"},{"cve":"CVE-2026-12051","cvss":4.6,"epss":0.0023,"slug":"cve-2026-12051-zephyr-usb-dfu-null-pointer-dereference-in-handle-download","title":"Zephyr USB DFU NULL pointer dereference in handle_download","severity":"medium","exploited":false,"published_at":"2026-08-11T06:17:12.62+00:00","url":"https://junglewise.ai/threats/cve-2026-12051-zephyr-usb-dfu-null-pointer-dereference-in-handle-download"},{"cve":"CVE-2026-8718","cvss":8.4,"epss":0.0016,"slug":"cve-2026-8718-zephyr-dtls-connection-id-buffer-overflow-in-getsockopt","title":"Zephyr DTLS Connection ID buffer overflow in getsockopt","severity":"high","exploited":false,"published_at":"2026-08-10T23:16:51.587+00:00","url":"https://junglewise.ai/threats/cve-2026-8718-zephyr-dtls-connection-id-buffer-overflow-in-getsockopt"},{"cve":"CVE-2026-11811","cvss":3.7,"epss":0.0041,"slug":"cve-2026-11811-zephyr-rtos-updatehub-socket-descriptor-leak-in-coap-dtls-setup","title":"Zephyr RTOS UpdateHub socket descriptor leak in CoAP/DTLS setup","severity":"low","exploited":false,"published_at":"2026-08-10T23:16:50.893+00:00","url":"https://junglewise.ai/threats/cve-2026-11811-zephyr-rtos-updatehub-socket-descriptor-leak-in-coap-dtls-setup"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"related":[{"name":"Zephyr Project Zephyr OS","slug":"zephyr-os","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/zephyr-os"}],"technology":{"hub":true,"name":"Zephyr Project Zephyr","slug":"zephyr","vendor":{"name":"Zephyr Project","slug":"zephyr-project","url":"https://junglewise.ai/threats/vendors/zephyr-project"},"aliases":["zephyr-rtos"],"category":"operating-system","homepage":"https://zephyrproject.org/","repo_url":"https://github.com/zephyrproject-rtos/zephyr","description":"Zephyr is a small, scalable real-time operating system (RTOS) optimized for resource-constrained devices across multiple architectures.","url":"https://junglewise.ai/threats/technologies/zephyr"},"most_severe":[{"cve":"CVE-2026-13214","cvss":9.8,"epss":0.0051,"slug":"cve-2026-13214-zephyr-ocpp-client-stack-buffer-overflow-in-getconfiguration","title":"Zephyr OCPP client stack buffer overflow in GetConfiguration handler","severity":"critical","exploited":false,"published_at":"2026-08-25T05:17:20.06+00:00","url":"https://junglewise.ai/threats/cve-2026-13214-zephyr-ocpp-client-stack-buffer-overflow-in-getconfiguration"},{"cve":"CVE-2026-5067","cvss":9.8,"slug":"cve-2026-5067-zephyr-rtos-stack-overflow-in-http-server-websocket-upgrade","title":"Zephyr RTOS stack overflow in HTTP server WebSocket upgrade","severity":"critical","exploited":false,"published_at":"2026-06-09T06:16:53.92+00:00","url":"https://junglewise.ai/threats/cve-2026-5067-zephyr-rtos-stack-overflow-in-http-server-websocket-upgrade"},{"cve":"CVE-2026-12366","cvss":8.8,"epss":0.0017,"slug":"cve-2026-12366-zephyr-use-after-free-in-dynamic-k-timer-cleanup","title":"Zephyr use-after-free in dynamic k_timer cleanup","severity":"high","exploited":false,"published_at":"2026-08-14T18:17:22.043+00:00","url":"https://junglewise.ai/threats/cve-2026-12366-zephyr-use-after-free-in-dynamic-k-timer-cleanup"},{"cve":"CVE-2026-9771","cvss":8.8,"epss":0.0014,"slug":"cve-2026-9771-zephyr-rtos-flash-copy-privilege-escalation-via-unvalidated-device","title":"Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointers","severity":"high","exploited":false,"published_at":"2026-08-17T17:16:57.72+00:00","url":"https://junglewise.ai/threats/cve-2026-9771-zephyr-rtos-flash-copy-privilege-escalation-via-unvalidated-device"},{"cve":"CVE-2026-10643","cvss":8.7,"slug":"cve-2026-10643-zephyr-rtos-heap-overflow-in-ip-socket-recvmsg-implementation","title":"Zephyr RTOS heap overflow in IP socket recvmsg implementation","severity":"high","exploited":false,"published_at":"2026-06-28T00:16:24.637+00:00","url":"https://junglewise.ai/threats/cve-2026-10643-zephyr-rtos-heap-overflow-in-ip-socket-recvmsg-implementation"},{"cve":"CVE-2026-8718","cvss":8.4,"epss":0.0016,"slug":"cve-2026-8718-zephyr-dtls-connection-id-buffer-overflow-in-getsockopt","title":"Zephyr DTLS Connection ID buffer overflow in getsockopt","severity":"high","exploited":false,"published_at":"2026-08-10T23:16:51.587+00:00","url":"https://junglewise.ai/threats/cve-2026-8718-zephyr-dtls-connection-id-buffer-overflow-in-getsockopt"},{"cve":"CVE-2026-10673","cvss":8.3,"slug":"cve-2026-10673-zephyr-adin2111-adin1110-ethernet-driver-out-of-bounds-write","title":"Zephyr ADIN2111/ADIN1110 Ethernet driver out-of-bounds write","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:44.18+00:00","url":"https://junglewise.ai/threats/cve-2026-10673-zephyr-adin2111-adin1110-ethernet-driver-out-of-bounds-write"},{"cve":"CVE-2026-10672","cvss":8.2,"slug":"cve-2026-10672-zephyr-rtos-out-of-bounds-read-in-lwm2m-firmware-pull-uri","title":"Zephyr RTOS out-of-bounds read in LwM2M firmware pull URI handling","severity":"high","exploited":false,"published_at":"2026-07-14T15:16:55.56+00:00","url":"https://junglewise.ai/threats/cve-2026-10672-zephyr-rtos-out-of-bounds-read-in-lwm2m-firmware-pull-uri"},{"cve":"CVE-2026-10678","cvss":8.1,"slug":"cve-2026-10678-zephyr-rtos-null-pointer-dereference-and-oob-write-in-mctp-i2c","title":"Zephyr RTOS NULL pointer dereference and OOB write in MCTP I2C+GPIO","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:00.047+00:00","url":"https://junglewise.ai/threats/cve-2026-10678-zephyr-rtos-null-pointer-dereference-and-oob-write-in-mctp-i2c"},{"cve":"CVE-2026-7656","cvss":8.1,"slug":"cve-2026-7656-zephyr-rtos-ipv6-neighbor-discovery-validation-bypass","title":"Zephyr RTOS IPv6 Neighbor Discovery validation bypass","severity":"high","exploited":false,"published_at":"2026-06-29T23:16:43.65+00:00","url":"https://junglewise.ai/threats/cve-2026-7656-zephyr-rtos-ipv6-neighbor-discovery-validation-bypass"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}