Espressif develops widely embedded microcontroller platforms and firmware development frameworks, particularly the ESP32 and ESP8266 series, which power a broad range of IoT devices, smart home products, and connected embedded systems deployed across consumer and industrial contexts. The vendor's vulnerability footprint, though modest in volume, reaches a prominent position in the landscape because of the ubiquity and long-lived nature of its deployed silicon and the supply-chain depth of its SDK and toolchain. A meaningful share of the vendor's disclosures reach serious severity, and the exposure recurs consistently across core products such as the ESP-IDF development framework and the ESP32/ESP8266 SoCs through weakness classes including improper input validation, buffer overflows, and out-of-bounds read and write conditions that are characteristic of constrained embedded firmware. Defenders should inventory Espressif-based devices in their environment and prioritize firmware updates for internet-connected or remotely managed instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Espressif over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45328HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c a | Jun 10, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-42854CRITICAL arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino | May 12, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-41429HIGH arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruptio | Apr 24, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-45541HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprot | Jun 10, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-45542HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SR | Jun 10, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-42855HIGH arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementa | May 12, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-66409CRITICAL ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VE | Dec 2, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-55297HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential hand | Aug 21, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-24893HIGH ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during prov | Jun 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-45160MEDIUM ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server opt | Jun 10, 2026 | 6.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Espressif.
Media articles that mention a CVE ID that affects a product developed by Espressif — matched by CVE ID, not by vendor name.