SEPTEMBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-77236

HIGH · CVSS 7.3 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

FreeRTOS-Kernel versions prior to 11.3.1 are vulnerable due to insufficient minimum size validation in secure context allocation, which could allow local users to perform out-of-bounds writes and corrupt secure-world heap metadata. This vulnerability poses a high risk, as it can lead to potential exploitation of the secure environment. Organizations utilizing FreeRTOS-Kernel should prioritize upgrading to version 11.3.1 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77236
Severity
HIGH
CVSS
7.3
EPSS
0.11%

Original NVD Description

Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later.

Related CVEs

Other vulnerabilities affecting the same vendor(s)