Zephyr RTOS: Six Vulnerabilities Including Two High-Severity Flaws Disclosed Together
A batch of six vulnerabilities, including two High severity flaws, were disclosed in the Zephyr RTOS on September 28-29, 2026, affecting networking and memory management.

Key findings
- Six vulnerabilities in Zephyr RTOS disclosed between September 28-29, 2026, ranging from Medium to High severity.
- Two High severity flaws (CVE-2026-16513, CVE-2026-18414) with CVSSv3 scores of 7.8 impact memory management and device drivers.
- Network-related vulnerabilities include issues in MCUmgr transport, IEEE 802.15.4 fragmentation, and LwM2M message handling.
- A critical userspace verifier flaw (CVE-2026-16513) allows potential kernel memory overwrite.
- Patches are available; users are urged to update to the latest Zephyr RTOS versions.
On September 28-29, 2026, a batch of six vulnerabilities was disclosed in the Zephyr RTOS, affecting various subsystems including networking, memory management, and device drivers. The vulnerabilities range in severity from Medium to High, with two critical flaws (CVE-2026-16513 and CVE-2026-18414) carrying a CVSSv3 score of 7.8. These disclosures highlight potential weaknesses in how the RTOS handles data validation, buffer management, and inter-process communication.
Several vulnerabilities stem from improper handling of network protocols and data. CVE-2026-18747, a Medium severity flaw, involves the MCUmgr SMP-over-console transport incorrectly decoding a base64 frame and verifying a CRC, potentially leading to processing of malformed data. Another network-related issue, CVE-2026-18415 (Medium severity), arises from the IEEE 802.15.4 layer's fixed-size transmit buffer, which can be overflowed when 6LoWPAN fragmentation is enabled by default. Additionally, CVE-2026-18414, a High severity vulnerability, points to a flaw in the ADC API where drivers might not adequately check the destination buffer size for sampling sequences, risking buffer overflows.
The networking stack is further impacted by CVE-2026-18416, a Medium severity vulnerability where the LwM2M message handling component mishandles CoAP WRITE/CREATE requests with Block1 options. This could allow an attacker to manipulate block sizes before proper validation. The native BSD-socket layer is affected by CVE-2026-18417 (Medium severity), which involves type-punning asynchronous socket errors into a struct net_context field, potentially leading to incorrect error handling.
A critical vulnerability, CVE-2026-16513 (High severity), resides in the userspace verifier for RTIO (Real-Time I/O) operations. It fails to validate an output parameter for RTIO object handles, allowing an attacker to potentially overwrite kernel memory by storing the kernel address of a syscall argument.
The disclosed vulnerabilities were patched in subsequent releases of the Zephyr RTOS. Users are advised to update to the latest versions to mitigate these risks. The batch of disclosures, occurring within a three-hour window, suggests a coordinated discovery or reporting of these issues.
This batch of vulnerabilities underscores the importance of rigorous input validation and secure memory management practices in embedded operating systems like Zephyr. The range of affected components, from low-level drivers to network protocols and syscall verification, indicates a need for comprehensive security audits across the entire codebase. Users should prioritize applying patches to protect against potential exploitation.
The disclosures were made on September 28-29, 2026. The affected versions and specific patch details can be found in the official Zephyr RTOS advisories.
CVE-2026-18747, CVE-2026-18416, CVE-2026-18417, CVE-2026-18415, CVE-2026-18414, CVE-2026-16513.