Skip to content
High-Risk Vulnerabilities in Zephyr RTOS Expose Kernel to Attacks

High-Risk Vulnerabilities in Zephyr RTOS Expose Kernel to Attacks

First seen 11 Oct 2026, 07:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC
  • •CVE-2026-19575 allows arbitrary code execution in supervisor mode.
  • •CVE-2026-19569 enables privilege escalation through heap corruption.
  • •Both vulnerabilities were published on 2026-10-09 and have high CVSS scores.

Two vulnerabilities, CVE-2026-19575 and CVE-2026-19569, were disclosed in Zephyr RTOS, impacting devices with enabled CONFIG_USERSPACE. CVE-2026-19575 allows arbitrary code execution in supervisor mode due to a type validation omission in the device deinitialization syscall. CVE-2026-19569 enables privilege escalation through heap memory corruption caused by unchecked arithmetic in dynamic object creation. Both vulnerabilities have a CVSS score of 7.8 and 8.8, respectively, and were published on 2026-10-09. Exploitation requires specific configurations, making them particularly dangerous for IoT and embedded systems. Patches have been released, but the vulnerabilities remain a significant threat to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-09
CVE-2026-19575 published
A vulnerability in Zephyr RTOS allows privilege escalation to execute arbitrary code in supervisor mode.
Ciberseguridadlatam
2026-10-09
CVE-2026-19569 published
A flaw in dynamic object creation allows userspace threads to escape the sandbox and write to kernel memory.
Ciberseguridadlatam

More articles in this cluster (2)

Following this threat?

Track CVE-2026-19569 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
Devices running Zephyr RTOS with CONFIG_USERSPACE and specific configurations enabled are affected.
Have these vulnerabilities been exploited in the wild?
No confirmed exploitation has been reported, but the vulnerabilities are serious and require immediate attention.
What should organizations do now?
Organizations should apply the patches released for both CVEs as soon as possible to mitigate risks.