runZero disclosed seven critical FatFs vulnerabilities (R0.16 and earlier) affecting millions of embedded devices, including USB drives, SD cards,
On July 1, 2026, cybersecurity firm runZero, specializing in network exposure management, formally disclosed that the FatFs file system module (versions R0.16 and earlier), widely used in small embedded systems, contains seven critical security vulnerabilities. These vulnerabilities were discovered by runZero's founder and CEO HD Moore through deep investigation of FAT and exFAT parsing mechanisms. The CVSS severity scores for the vulnerabilities vary; CVE-2026-6682, CVE-2026-6687, and CVE-2026-6688 are rated as high-risk with CVSS scores up to 7.6; CVE-2026-6685 is medium-risk (6.1); while CVE-2026-6683, CVE-2026-6684, and CVE-2026-6686 are medium-risk (4.6)[6][2]. Notably, HD Moore attempted to contact FatFs maintainer ChaN in late April without success, sought coordination via JPCERT/CC but received no response, and ultimately communicated with major downstream vendors in mid-May before publicly disclosing the vulnerabilities on July 1[6].
FatFs is a general-purpose FAT/exFAT file system module designed for resource-constrained small MCUs, unrestricted by platform or storage device. Its core vulnerabilities involve memory corruption, integer overflow, logic errors, and information leakage. According to technical details, the most severe CVE-2026-6682 is an integer overflow located in the mount_volume() function, which may occur when executing fasize *= fs->n_fats, potentially causing value wrap and enabling attackers to tamper with file size metadata, leading to downstream exploitation[2][3]. Another high-risk vulnerability, CVE-2026-6687, is a stack overflow related to exFAT label handling, occurring in the f_getlabel() function, which may cause memory corruption or code execution[2]. Additionally, these vulnerabilities can be triggered via carefully crafted USB drives, SD cards, or mounted firmware update images, resulting in memory corruption, denial of service, silent data corruption, and potential code execution[2]. runZero's research team utilized Visual Studio Code, GitHub Copilot's automatic mode, and fuzzing tools to successfully discover trivial vulnerabilities missed by manual audits and verified their actual exploitability across various embedded scenarios[6].
Since FatFs is widely "vended" (directly embedded) into multiple mainstream open-source ecosystems, its impact scope is extensive, covering consumer IoT devices, industrial controllers, drones, crypto wallets, and other products. Key affected ecosystems include: STMicroelectronics' STM32Cube middleware (STM32 is the MCU with the highest global market share), Espressif's ESP-IDF framework (ESP32 series has extremely high shipment volume), Zephyr RTOS (an open-source operating system led by the Linux Foundation), and ArduPilot (widely used in drones and autonomous driving devices)[2][6]. runZero warns that if attackers gain physical access to vulnerable devices (e.g., inserting malicious USB or SD cards), systems may be "jailbroken" or fully compromised in the absence of ASLR (Address Space Layout Randomization) and memory protection[6]. However, for general users with only brief access to devices (e.g., using network video cameras, voting machines, ATMs, or touchscreen devices), the risk is relatively low and does not lead to full system compromise[6]. The research team has released proof-of-concept images, test architectures, and QEMU-based exploitation examples; downstream vendors identifying and fixing their bundled versions may take several years[2].
In the current situation lacking complete upstream patches (only CVE-2026-6684 is patched in FatFs R0.16, and CVE-2026-6683 has only partial protection), device vendors and users should adopt the following protective measures: First, strictly disable untrusted USB storage devices or SD cards, restrict access to untrusted FAT/exFAT media, and prevent automatic mounting of malicious images[1][6]. Second, disable unnecessary exFAT support, as some high-risk vulnerabilities (e.g., CVE-2026-6687) are directly related to exFAT label handling[2]. Third, downstream vendors should independently add additional checks and protection logic in their code, such as validating file size metadata to prevent integer overflow and strengthening stack protection to resist overflow attacks[1][2]. ReconShield Intelligence recommends enterprises execute three steps for detection and response and guides device vendors to take five steps to enhance security[6]. Due to the lack of coordination and maintainer response, proactive defense and downstream self-patching have become the key strategies currently.
5-Step Patch Checklist
mount_volume().