SecAlerts
Z

Zephyr Project

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 37 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 15, 2024 to present

37
Total CVEs
18
Critical+High
0
Exploited
18
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
18
Critical/High
Risk Level
49/100
medium
📈 2 in Last 30 Days

Severity Distribution

Critical
2
High
16
Medium
17
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Use After Free
8
2
Null Pointer Dereference
4
3
Input Validation
2
4
Infoleak
1
5
Race Condition
1

Most Affected Products

1. zephyrproject zephyr34
2. Zephyr Project Zephyr21
3. Zephyr Project Zephyr RTOS5
4. Zephyr Project Zephyr OS3
5. Zephyr Project Zephyr Bluetooth Classic (BR/EDR) L2CAP (bt_l2cap_br)1

Recent Vulnerabilities

See more →
CVE-2026-15893
CVSS 6.5medium

Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS

Sep 14, 2026🔧 No Patch
CVE-2026-15460
CVSS 5.4medium

Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path

Sep 9, 2026🔧 No Patch
CVE-2026-13216
CVSS 6.1medium

Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length

Aug 25, 2026🔧 No Patch
CVE-2026-12366
CVSS 8.8high

Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal

Aug 14, 2026🔧 No Patch
CVE-2026-11985
CVSS 3.6low

Cross-thread FPU register leak on ARM when FPU enabled without register sharing

Aug 11, 2026🔧 No Patch
CVE-2026-10848
CVSS 8.6high

Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)

Aug 2, 2026🔧 No Patch
CVE-2026-10686
CVSS 7.5high

Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers

Jul 31, 2026🔧 No Patch
CVE-2026-10681
CVSS 7.0high

SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot

Jul 25, 2026🔧 No Patch
CVE-2026-10678
CVSS 8.1high

NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller

Jul 21, 2026🔧 No Patch
CVE-2026-10666
CVSS 9.8critical

Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`

Jul 12, 2026🔧 No Patch

Monitor Zephyr Project in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.