Known Vulnerabilities for Zephyr by Zephyrproject-rtos
Listed below are 10 of the newest known vulnerabilities associated with "Zephyr" by "Zephyrproject-rtos".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90257 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info strin... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-76931 json | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter ... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-16515 json | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (d... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-15924 json | Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cache... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-15923 json | The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop t... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-14366 json | The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a networ... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-13735 json | Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_me... | Not Provided | 2026-08-28 | 2026-09-01 |
| CVE-2026-13734 json | Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated... | Not Provided | 2026-08-28 | 2026-09-01 |
| CVE-2026-13478 json | The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passin... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-13351 json | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number o... | Not Provided | 2026-06-25 | 2026-06-25 |