CVE Tools

Zephyr

263 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Zephyr, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Zephyr CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Zephyr CVEs per month
MonthCVEs
2024-103
2024-111
2024-121
2025-010
2025-024
2025-030
2025-040
2025-050
2025-061
2025-070
2025-081
2025-094
2025-100
2025-116
2025-121
2026-011
2026-020
2026-035
2026-041
2026-054
2026-0630
2026-0728
2026-0857
2026-0918

Severity

How the 263 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical166%
  • High9135%
  • Medium13451%
  • Low228%

Latest CVEs

The 15 most recently published vulnerabilities affecting Zephyr.

  1. CVE-2026-17054Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly5.3
  2. CVE-2026-15890AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization5.3
  3. CVE-2026-17052Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allows arbitrary supervisor-memory write from userspace7.8
  4. CVE-2026-17051Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell length6.0
  5. CVE-2026-17050Double free of the USB host configuration descriptor when device enumeration fails5.7
  6. CVE-2026-16515ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack4.7
  7. CVE-2026-16514Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved4.3
  8. CVE-2026-16512Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames3.1
  9. CVE-2026-14986Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction6.8
  10. CVE-2026-16148Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work item4.6
  11. CVE-2026-16147it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruption6.8
  12. CVE-2026-15924Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets5.9
  13. CVE-2026-15893Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS6.5
  14. CVE-2026-15923Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size4.6
  15. CVE-2026-15892Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store