The CVE-2026-77236 vulnerability in FreeRTOS-Kernel before version 11.3.1 involves a missing minimum size validation in secure context allocation. This issue could potentially allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. The vulnerability has a CVSS score of 8.3 and is classified as HIGH severity. Affected product deployments s [truncated]
A missing bounds validation vulnerability in the MQTT v5.0 property parser of FreeRTOS coreMQTT 5.0.0 allows an MQTT broker to cause denial of service via a crafted packet. The vulnerability was published on 2026-05-15 and last modified on 2026-05-19. The issue is rated HIGH severity with a CVSS score of 8.7. The root cause is identified as CWE-125 (Out-of-bounds Read). FreeRTOS has released coreMQTT vers [truncated]