Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-2026-77235: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected. - CVE-2026-77236: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected. - CVE-2026-77237: This issue affects builds with queue sets enabled; applications built without queue sets are not affected. Impacted versions: - CVE-2026-77234: >=7.0.0 AND <=11.3.0 (MPU-enabled ports) - CVE-2026-77235: >=10.2.0 AND <=11.3.0 (ARMv8-M ports with TrustZone + MPU) - CVE-2026-77236: >=10.2.0 AND <=11.3.0 (ARMv8-M ports with TrustZone) - CVE-2026-77237: >=7.4.0 AND <=11.3.0 (MPU-enabled ports with configUSE_QUEUE_SETS=1) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Four privilege escalation and memory safety issues in FreeRTOS-Kernel affecting MPU, ARM TrustZone, and queue set configurations.
- Who is affected
- Microcontroller and embedded systems deployments using affected FreeRTOS-Kernel versions with MPU, ARM TrustZone secure contexts, or queue sets enabled.
- Urgency
- High; privilege escalation in embedded real-time systems can compromise device security and control; applicable only to specific configurations.
- Action
- Upgrade to patched FreeRTOS-Kernel version from AWS; verify if your build uses affected features (MPU, TrustZone, queue sets).
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreeRTOS-Kernel
Get an email when a new FreeRTOS-Kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-772340.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-772350.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-772360.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-772370.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-77234 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77235 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77236 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77237 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-77237: Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 mig…nvd
- highCVE-2026-77236: Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 …nvd
- highCVE-2026-77235: Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before…nvd
- highCVE-2026-77234: Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on…nvd
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownCVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation2026-08-20
- unknownOngoing updates on Copy.fail and variants2026-08-20