Vendor
Zephyr Project vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 94 vulnerabilities in Zephyr Project: 2 in the last 7 days and 66 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15890, was published on 21 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 2
- Last 90 days
- 66
- Critical, all time
- 2
- Exploited in the wild
- 0
About Zephyr Project
The Zephyr Project is a collaborative effort hosted by the Linux Foundation to develop a real-time operating system for resource-constrained devices.
Zephyr Project technologies
Latest Zephyr Project vulnerabilities
- CVE-2026-15890: Zephyr PSA Trusted Storage AEAD nonce reuse in concurrent writesmediumCVSS 5.3EPSS 0.1%
- CVE-2026-17050: Zephyr RTOS USB host stack double-free in configuration descriptormediumCVSS 5.7EPSS 0.2%
- CVE-2026-16514: Zephyr RTOS gPTP out-of-bounds read in Announce message handlingmediumCVSS 4.3EPSS 0.2%
- CVE-2026-16512: Zephyr RTOS gPTP message header out-of-bounds readlowCVSS 3.1EPSS 0.2%
- CVE-2026-15893: Zephyr RTOS IPv6 reachable time calculation denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-15891: Zephyr MQTT-SN client NULL pointer dereference in keepalive handlerhighCVSS 7.5EPSS 0.3%
- CVE-2026-76931: Zephyr Project Manager stored cross-site scripting in message parametermediumCVSS 6.4EPSS 0.3%
- CVE-2026-14697: Zephyr RTOS IPv6 Neighbor Solicitation packet leak denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-14696: Zephyr RTOS Ethernet bridge packet leak denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-13735: Zephyr WireGuard authentication bypass in keepalive handlinglowCVSS 3.7EPSS 0.3%
- CVE-2026-13734: Zephyr WireGuard replay validation bypass in data-plane handlermediumCVSS 6.5EPSS 0.3%
- CVE-2026-13481: Zephyr RTOS PTP management-message parser out-of-bounds read in tlv.cmediumCVSS 5.4EPSS 0.3%
- CVE-2026-13480: Zephyr LoRaWAN TS004 buffer over-read in frag_transport_package_callbacklowCVSS 3.1EPSS 0.3%
- CVE-2026-13479: Zephyr RTOS LoRaWAN clock-sync buffer over-readlowCVSS 3.1EPSS 0.2%
- CVE-2026-13216: Zephyr virtio PCI driver stack buffer overflow in capability parsingmediumCVSS 6.1EPSS 0.2%
- CVE-2026-13215: Zephyr ext2 filesystem driver superblock validation bypassmediumCVSS 6.8EPSS 0.2%
- CVE-2026-13214: Zephyr OCPP client stack buffer overflow in GetConfiguration handlercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-9728: Zephyr mailbox TOCTOU race in syscall verifiermediumCVSS 6.4EPSS 0.1%
- CVE-2026-9771: Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointershighCVSS 8.8EPSS 0.1%
- CVE-2026-12366: Zephyr use-after-free in dynamic k_timer cleanuphighCVSS 8.8EPSS 0.2%
- CVE-2026-12365: Zephyr work queue use-after-free in timeout handlingmediumCVSS 5.8EPSS 0.1%
- CVE-2026-12364: Zephyr OS logging system-call validation bypasshighCVSS 8.4EPSS 0.2%
- CVE-2026-12234: Zephyr TOCTOU in userspace syscall verifiers sendmsg/recvmsghighCVSS 7.8EPSS 0.1%
- CVE-2026-12233: Zephyr PSA Protected Storage uninitialized mutex denial of servicemediumCVSS 5.9EPSS 0.5%
- CVE-2026-12232: Intel ALH digital-audio-interface driver information disclosuremediumCVSS 6.1EPSS 0.1%
Most severe Zephyr Project vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-13214: Zephyr OCPP client stack buffer overflow in GetConfiguration handlercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-5067: Zephyr RTOS stack overflow in HTTP server WebSocket upgradecriticalCVSS 9.8
- CVE-2026-12366: Zephyr use-after-free in dynamic k_timer cleanuphighCVSS 8.8EPSS 0.2%
- CVE-2026-9771: Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointershighCVSS 8.8EPSS 0.1%
- CVE-2026-10643: Zephyr RTOS heap overflow in IP socket recvmsg implementationhighCVSS 8.7
- CVE-2026-12364: Zephyr OS logging system-call validation bypasshighCVSS 8.4EPSS 0.2%
- CVE-2026-8718: Zephyr DTLS Connection ID buffer overflow in getsockopthighCVSS 8.4EPSS 0.2%
- CVE-2026-10673: Zephyr ADIN2111/ADIN1110 Ethernet driver out-of-bounds writehighCVSS 8.3
- CVE-2026-10672: Zephyr RTOS out-of-bounds read in LwM2M firmware pull URI handlinghighCVSS 8.2
- CVE-2026-10678: Zephyr RTOS NULL pointer dereference and OOB write in MCTP I2C+GPIOhighCVSS 8.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 11 | 0 | |
| 6 Jul 2026 | 8 | 0 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 8 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 9 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 9 | 1 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 3 | 0 | |
| 21 Sep 2026 | 2 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/zephyr-project.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Zephyr Project vulnerabilities", https://junglewise.ai/threats/vendors/zephyr-project, 26 September 2026.