Zephyr
263 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Zephyr, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Zephyr CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 3 |
| 2024-11 | 1 |
| 2024-12 | 1 |
| 2025-01 | 0 |
| 2025-02 | 4 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 4 |
| 2025-10 | 0 |
| 2025-11 | 6 |
| 2025-12 | 1 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 5 |
| 2026-04 | 1 |
| 2026-05 | 4 |
| 2026-06 | 30 |
| 2026-07 | 28 |
| 2026-08 | 57 |
| 2026-09 | 18 |
Severity
How the 263 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical16
- High91
- Medium134
- Low22
Latest CVEs
The 15 most recently published vulnerabilities affecting Zephyr.
- CVE-2026-17054Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly5.3
- CVE-2026-15890AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization5.3
- CVE-2026-17052Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allows arbitrary supervisor-memory write from userspace7.8
- CVE-2026-17051Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell length6.0
- CVE-2026-17050Double free of the USB host configuration descriptor when device enumeration fails5.7
- CVE-2026-16515ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack4.7
- CVE-2026-16514Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved4.3
- CVE-2026-16512Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames3.1
- CVE-2026-14986Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction6.8
- CVE-2026-16148Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work item4.6
- CVE-2026-16147it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruption6.8
- CVE-2026-15924Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets5.9
- CVE-2026-15893Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS6.5
- CVE-2026-15923Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size4.6
- CVE-2026-15892Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service5.3
Product grouping is registry-driven, with AI assist and human review. How it works