Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zephyrproject

First CVE: Sep 6, 2018Active for: 8 yearsTotal CVEs: 175
38.9
VTI Score
Medium

Zephyr is a real-time operating system and embedded-systems framework widely deployed across IoT devices, microcontrollers, and edge platforms, creating a distributed and heterogeneous attack surface spanning numerous downstream products. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in memory-safety weaknesses including out-of-bounds writes, classic and heap-based buffer overflows, stack-based buffer overflows, and improper input validation—classes endemic to systems-level code and bare-metal environments where bounds checking is often minimal or absent. The recurring exposure pattern reflects Zephyr's role as a foundational OS layer and its use across deeply embedded and resource-constrained devices where remediation cycles are lengthy and fragmented; defenders should treat patches for this vendor as broadly applicable to the embedded and IoT tier of their infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
175
Total CVEs
More Total CVEs than 100% of tracked vendors
19.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zephyrproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2018
7 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (175 CVEs).

175 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-10666CRITICAL
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipad
Jul 12, 20269.843NONO
CVE-2026-5067CRITICAL
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header par
Jun 9, 20269.839NONO
CVE-2026-10643HIGH
Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payl
Jun 27, 20267.837NONO
CVE-2026-10667HIGH
Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel object
Jul 12, 20267.836NONO
CVE-2026-10665HIGH
In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbound transport-data payload into a fixed pool buffer of CONFIG
Jul 12, 20267.436NONO
CVE-2026-10673HIGH
The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (OA) SPI mode by copying device-
Jul 15, 20268.335NONO
CVE-2026-10672HIGH
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) wit
Jul 14, 20268.235NONO
CVE-2026-10653HIGH
The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count at the start of each variable/he
Jun 30, 20268.135NONO
CVE-2026-9263HIGH
The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per the Bluet
Jun 30, 20268.135NONO
CVE-2026-8023HIGH
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files
Jun 29, 20267.535NONO
View all 175 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products175 CVEs
38%
43%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local38 (21.7%)
Network63 (36.0%)
Unknown0 (0.0%)
Physical12 (6.9%)
Adjacent Network62 (35.4%)
Attack Complexity
Low156 (89.1%)
High19 (10.9%)
Unknown0 (0.0%)
User Interaction
None173 (98.9%)
Unknown0 (0.0%)
Required2 (1.1%)
Privileges Required
Low38 (21.7%)
High4 (2.3%)
None133 (76.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (175 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zephyrproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zephyrproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zephyrproject's Products

View all 3 CNAs →

Top CWEs