SecAlerts
Z

Zephyr Project

Security Risk Profile

51
/100
medium

Security Risk Score

Comprehensive risk assessment based on 34 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 15, 2024 to present

34
Total CVEs
18
Critical+High
0
Exploited
18
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
18
Critical/High
Risk Level
51/100
medium
🆕 1Fresh (<7d)📈 6 in Last 30 Days

Severity Distribution

Critical
2
High
16
Medium
14
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Use After Free
8
2
Null Pointer Dereference
4
3
Input Validation
2
4
Infoleak
1
5
Race Condition
1

Most Affected Products

1. zephyrproject zephyr34
2. Zephyr Project Zephyr19
3. Zephyr Project Zephyr RTOS5
4. Zephyr Project Zephyr OS3
5. Zephyr Project Zephyr RTOS (ARM port)1

Recent Vulnerabilities

See more →
CVE-2026-12366
CVSS 8.8high

Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal

Aug 14, 2026🔧 No Patch
CVE-2026-11985
CVSS 3.6low

Cross-thread FPU register leak on ARM when FPU enabled without register sharing

Aug 11, 2026🔧 No Patch
CVE-2026-10848
CVSS 8.6high

Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)

Aug 2, 2026🔧 No Patch
CVE-2026-10686
CVSS 7.5high

Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers

Jul 31, 2026🔧 No Patch
CVE-2026-10681
CVSS 7.0high

SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot

Jul 25, 2026🔧 No Patch
CVE-2026-10678
CVSS 8.1high

NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller

Jul 21, 2026🔧 No Patch
CVE-2026-10666
CVSS 9.8critical

Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`

Jul 12, 2026🔧 No Patch
CVE-2026-10667
CVSS 7.8high

SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads

Jul 12, 2026🔧 No Patch
CVE-2026-10665
CVSS 7.4high

Heap buffer overflow on WireGuard receive path via unbounded incoming packet length

Jul 12, 2026🔧 No Patch
CVE-2026-10663
CVSS 6.1medium

Use-after-free / double-free of the root USB device in the experimental USB host stack

Jul 12, 2026🔧 No Patch

Monitor Zephyr Project in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.