Freertos
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Freertos product.
RSS Feeds for Freertos security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Freertos products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Freertos Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 5 vulnerabilities in Freertos with an average score of 7.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 5 | 7.48 |
It may take a day or so for new Freertos vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Freertos Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-77237 | Aug 21, 2026 |
FreeRTOS-Kernel <11.3.1 QueueSet Access Validation Bug Unlocks Privileged MemoryMissing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later. |
|
| CVE-2026-77236 | Aug 21, 2026 |
FreeRTOSKernel 11.3.0: Heap Metadata OOB via Undersized StackMissing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later. |
|
| CVE-2026-77235 | Aug 21, 2026 |
UAF via Missing Priv Verif in Secure Context Clean FreeRTOS-Kernel <11.3.1Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. |
|
| CVE-2026-77234 | Aug 21, 2026 |
FreeRTOS Kernel <11.3.1 Improper Input Validation Enables Privileged ExecutionImproper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later. |
|
| CVE-2026-8686 | May 15, 2026 |
coreMQTT v5.0.1 DOS via Missing Bounds Validation in MQTT v5.0 Prop ParserMissing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. |
|