Ciberseguridadlatam High-Risk Vulnerabilities in Zephyr RTOS Expose Kernel to Attacks
Article Content
- •CVE-2026-19575 allows arbitrary code execution in supervisor mode.
- •CVE-2026-19569 enables privilege escalation through heap corruption.
- •Both vulnerabilities were published on 2026-10-09 and have high CVSS scores.
Two vulnerabilities, CVE-2026-19575 and CVE-2026-19569, were disclosed in Zephyr RTOS, impacting devices with enabled CONFIG_USERSPACE. CVE-2026-19575 allows arbitrary code execution in supervisor mode due to a type validation omission in the device deinitialization syscall. CVE-2026-19569 enables privilege escalation through heap memory corruption caused by unchecked arithmetic in dynamic object creation. Both vulnerabilities have a CVSS score of 7.8 and 8.8, respectively, and were published on 2026-10-09. Exploitation requires specific configurations, making them particularly dangerous for IoT and embedded systems. Patches have been released, but the vulnerabilities remain a significant threat to affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-19569 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
Have these vulnerabilities been exploited in the wild?
What should organizations do now?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…