CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Seven Unpatched FatFs Flaws Expose Millions of Embedded Devices to Code Execution

July 3, 2026

Security firm runZero has disclosed seven unpatched vulnerabilities in FatFs, a widely used filesystem library for FAT and exFAT formats, embedded in millions of devices including security cameras, drones, industrial controllers, and crypto wallets. The flaws allow attackers with physical access via USB drives or SD cards to corrupt memory and execute arbitrary code. The most severe, CVE-2026-6682 (CVSS 7.6), is an integer overflow in FAT32 mount handling. Other high-severity bugs include CVE-2026-6687 (exFAT buffer overflow) and CVE-2026-6688 (long filename overflow). runZero attempted to contact the FatFs maintainer and JPCERT/CC without response; only CVE-2026-6684 is fixed upstream in FatFs R0.16. Affected platforms include Espressif ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, and SWUpdate. No active exploits have been reported, but proof-of-concept code is public. runZero discovered the bugs using an AI-assisted fuzzer, highlighting the growing role of AI in vulnerability research. Downstream fixes are expected to take years, echoing the slow patching of the 2024 PixieFail bugs.

CVEs: CVE-2026-6682, CVE-2026-6687, CVE-2026-6688, CVE-2026-6685, CVE-2026-6683, CVE-2026-6686, CVE-2026-6684, CVE-2026-55200, CVE-2026-46817

Companies: runZero, Espressif, STMicroelectronics, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung, JPCERT/CC

Products: FatFs, Espressif ESP-IDF, STMicroelectronics STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, SWUpdate