PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8686 FreeRTOS CVE debrief

A missing bounds validation vulnerability in the MQTT v5.0 property parser of FreeRTOS coreMQTT 5.0.0 allows an MQTT broker to cause denial of service via a crafted packet. The vulnerability was published on 2026-05-15 and last modified on 2026-05-19. The issue is rated HIGH severity with a CVSS score of 8.7. The root cause is identified as CWE-125 (Out-of-bounds Read). FreeRTOS has released coreMQTT version 5.0.1 to address this vulnerability.

Vendor
FreeRTOS
Product
coreMQTT
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-15
Original CVE updated
2026-05-19
Advisory published
2026-05-15
Advisory updated
2026-05-19

Who should care

Organizations deploying FreeRTOS coreMQTT 5.0.0 in IoT and embedded systems, particularly those connecting to external or untrusted MQTT brokers. Development teams building MQTT-based applications on constrained devices using the FreeRTOS ecosystem.

Technical summary

The vulnerability exists in the MQTT v5.0 property parser implementation within FreeRTOS coreMQTT 5.0.0. Insufficient bounds validation when processing incoming MQTT packets allows a malicious or compromised MQTT broker to send crafted packets that trigger an out-of-bounds read condition. This results in denial of service for the MQTT client application. The attack vector is network-based, requires no authentication, and can be exploited without user interaction. The vulnerability does not affect confidentiality or integrity but has high impact on availability.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade FreeRTOS coreMQTT to version 5.0.1 or later
  • Review MQTT broker connections for unexpected traffic patterns
  • Monitor for denial-of-service indicators in MQTT client applications
  • Validate MQTT packet handling in embedded deployments using coreMQTT

Evidence notes

CVE published 2026-05-15; modified 2026-05-19. CVSS 4.0 vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N. Affected product: FreeRTOS coreMQTT 5.0.0. CWE-125 identified as weakness type.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8686 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8686

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8686 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8686

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-032-aws/

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/FreeRTOS/coreMQTT/releases/tag/v5.0.1

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Release Notes

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/FreeRTOS/coreMQTT/security/advisories/GHSA-6qh9-r6jp-2wxc

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.