CVE Tools

Freertos

23 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Freertos, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

Freertos CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Freertos CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-084
2026-090

Severity

How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical418%
  • High1045%
  • Medium836%

Latest CVEs

The 15 most recently published vulnerabilities affecting Freertos.

  1. CVE-2026-77237Missing type validation in xQueueAddToSet in FreeRTOS-Kernel6.5
  2. CVE-2026-77236Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel7.3
  3. CVE-2026-77235Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel7.3
  4. CVE-2026-77234Improper input validation in FreeRTOS-Kernel timer command handling8.8
  5. CVE-2025-5688Out of Bounds Write in FreeRTOS-Plus-TCP—
  6. CVE-2024-38373FreeRTOS-Plus-TCP Buffer Over-Read in DNS Response Parser9.6
  7. CVE-2024-28115Privilege Escalation in FreeRTOS Kernel ARMv7-M MPU ports and ARMv8-M ports with MPU support enabled8.8
  8. CVE-2021-27504Texas Instruments FREERTOS Integer Overflow or Wraparound7.4
  9. CVE-2021-43997FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a t...7.8
  10. CVE-2021-32020The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.9.8
  11. CVE-2021-31572The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.9.8
  12. CVE-2021-31571The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.9.8
  13. CVE-2018-16526Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to leak information or ...8.1
  14. CVE-2018-16602An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memo...5.9
  15. CVE-2018-16600An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memo...5.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store