PatchSiren cyber security CVE debrief
CVE-2026-8686 FreeRTOS CVE debrief
A missing bounds validation vulnerability in the MQTT v5.0 property parser of FreeRTOS coreMQTT 5.0.0 allows an MQTT broker to cause denial of service via a crafted packet. The vulnerability was published on 2026-05-15 and last modified on 2026-05-19. The issue is rated HIGH severity with a CVSS score of 8.7. The root cause is identified as CWE-125 (Out-of-bounds Read). FreeRTOS has released coreMQTT version 5.0.1 to address this vulnerability.
- Vendor
- FreeRTOS
- Product
- coreMQTT
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-19
Who should care
Organizations deploying FreeRTOS coreMQTT 5.0.0 in IoT and embedded systems, particularly those connecting to external or untrusted MQTT brokers. Development teams building MQTT-based applications on constrained devices using the FreeRTOS ecosystem.
Technical summary
The vulnerability exists in the MQTT v5.0 property parser implementation within FreeRTOS coreMQTT 5.0.0. Insufficient bounds validation when processing incoming MQTT packets allows a malicious or compromised MQTT broker to send crafted packets that trigger an out-of-bounds read condition. This results in denial of service for the MQTT client application. The attack vector is network-based, requires no authentication, and can be exploited without user interaction. The vulnerability does not affect confidentiality or integrity but has high impact on availability.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade FreeRTOS coreMQTT to version 5.0.1 or later
- Review MQTT broker connections for unexpected traffic patterns
- Monitor for denial-of-service indicators in MQTT client applications
- Validate MQTT packet handling in embedded deployments using coreMQTT
Evidence notes
CVE published 2026-05-15; modified 2026-05-19. CVSS 4.0 vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N. Affected product: FreeRTOS coreMQTT 5.0.0. CWE-125 identified as weakness type.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8686 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8686
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8686 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8686
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://aws.amazon.com/security/security-bulletins/2026-032-aws/
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/FreeRTOS/coreMQTT/releases/tag/v5.0.1
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/FreeRTOS/coreMQTT/security/advisories/GHSA-6qh9-r6jp-2wxc
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.