CVE-2026-6682Disclosure(elm-chan / fatfs)

HIGHCVSS 7.6 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch elm-chan fatfs systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). Remote delivery is also possible in OTA/update pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fatfs

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 3 mentions (2026-07-04); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
fatfs

Deep dive

Activity timeline13 mentions / 7d
01223Mentions · 2026-07-04: 3Mentions · 2026-07-06: 3Mentions · 2026-07-07: 3Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-08-05: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-07-04: 2PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-09: 1Exploit Tool / Code · 2026-07-04: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-07-09: 1Active Exploitation · 2026-07-09: 1Patch / Workaround · 2026-07-04: 3Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-04: 3Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 2Technical Details · 2026-08-05: 1Technical Details · 2026-09-16: 107-0407-0607-0707-0807-0908-0509-16
Signal classification5 categories
Disclosure
753.8%
PoC
215.4%
General
215.4%
False Positive
17.7%
Patch
17.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-07-043
Disclosure3
2026-07-063
Disclosure2False Positive1
2026-07-073
Disclosure1Patch1PoC1
2026-07-081
General1
2026-07-091
PoC1
2026-08-051
General1
2026-09-161
Disclosure1
Full discourse13 posts
  • The Hacker News@TheHackersNews
    Disclosure

    FatFs is buried inside devices that read USB drives, SD cards, and firmware images. @runZeroInc found 7 vulnerabilities in the library. Six still have no upstream fix, leaving vendors that bundle FatFs to patch on their own. The worst bug is CVE-2026-6682. https://t.co/L697SNe0mW

    Post summary

    The tweet announces seven vulnerabilities in the FatFs library, identifies CVE-2026-6682 as the most serious, and notes that most have no upstream fix, so vendors must patch manually.

    1283911931.8K
    2.3M followersView on X
  • Jλckλι@J4ck3LSyN
    PoC

    Just got command execution on a cheap amazon camera via integer overflow (CVE-2026-6682). Honestly was pretty plug-n-play. [Repo]: https://github.com/runZeroInc/vulns-2026-fatfs-chance I will release a report after the 60 day window (Even tho it cannot be patched on wild devices) #CyberSecurity #InfoSec https://t.co/cHDlC0bPer

    Post summary

    The author demonstrates command‑execution via an integer overflow (CVE‑2026‑6682) on an Amazon camera, shares a plug‑n‑play PoC in a GitHub repo, and notes the device cannot be patched.

    111130174.7K
    438 followersView on X
  • Mr. OS@ksg93rd
    PoC

    #AppSec #Threat_Research 1⃣ Veeam Backup Authenticated RCE Explained https://blog.securelayer7.net/cve-2026-44963-veeam-backup-authenticated-rce-binaryformatter-bypass // CVE-2026-44963 2⃣ Multiple LPE Vulnerabilities in Little Orbit GFAC Driver (GFAC_Sys_x64.sys) https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168 3⃣ Seven FatFs bugs, one very large blast radius https://www.runzero.com/blog/fatfs-bugs // CVE-2026-6682 - CVE-2026-6688 + PoCs https://github.com/runZeroInc/vulns-2026-fatfs-chance http://www.cyberpocket.org

    Post summary

    The post highlights several CVEs and provides links to repositories containing PoC code, giving technical detail but no evidence of active exploitation or patches.

    0701661.1K
    3.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Siber güvenlik şirketi runZero tarafından, yaygın olarak kullanılan FatFs dosya sistemi kütüphanesinde 7 güvenlik açığı tespit edildi. Güvenlik kameraları, IoT cihazları, dronlar ve birçok gömülü sistem potansiyel olarak etkilenebilir. En kritik açık CVE-2026-6682 (CVSS 7.6), özel hazırlanmış FAT32/exFAT medya üzerinden bellek bozulmasına (memory corruption) ve bazı senaryolarda uzaktan kod çalıştırmaya (RCE) yol açabiliyor. Tespit edilen CVE'ler: • CVE-2026-6682 – Integer overflow → Memory corruption / RCE • CVE-2026-6683 – exFAT divide-by-zero (DoS) • CVE-2026-6684 – Bozuk GPT partition tablosu ile DoS • CVE-2026-6685 – Cache hesaplama hatası, veri bozulması • CVE-2026-6686 – Bilgi sızıntısı • CVE-2026-6687 – exFAT volume label buffer overflow • CVE-2026-6688 – Long File Name (LFN) buffer overflow Şu ana kadar aktif istismar raporlanmadı. Ancak PoC'ler genele açık durumda. FAT/FAT32/exFAT kullanan gömülü sistem geliştiren üreticilerin FatFs entegrasyonlarını gözden geçirerek gerekli güvenlik güncellemelerini yayınlaması önem taşıyor.

    Post summary

    runZero disclosed seven FatFs CVEs with publicly available PoCs, no active exploitation yet, and urges manufacturers to release security updates.

    01072828
    2.2K followersView on X
  • Ryx@PadhiyarRushi
    Disclosure

    FatFs still deserves more attention than it gets. Seven bugs (CVE-2026-6682 et al.) in the library that sits under ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, TizenRT, SWUpdate and a long tail of IoT/industrial devices. Headline issue is an integer overflow in mount_volume() that can turn attacker-controlled filesystem metadata into a controlled read length. Crafted FAT/exFAT images via USB/SD or OTA remain a practical delivery path. https://www.runzero.com/blog/fatfs-bugs/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Embedded #IoTSecurity

    Post summary

    The text announces seven CVEs in the FatFs library (CVE-2026-6682 et al.) with technical details about an integer overflow in mount_volume() but provides no PoC, exploit tool, patch, or active exploitation evidence, functioning primarily as a vulnerability disclosure with a link to a blog post.

    32031491
    946 followersView on X
  • connect24h@connect24h
    Disclosure

    USB/SDを読むだけの部品が、組込機器の侵入口になる。FatFsで7件、CVE-2026-6682/6687/6688はいずれもCVSS 7.6。カメラ、ドローン、産業制御、hardware walletまで波及する話だ。 嫌なのは、攻撃面がUSBメディア、SDカード、firmware updateに寄っている点。現場では見落とされがちだが、ここは普通に初動対象に入れるべき。FatFs同梱有無、ESP-IDF/STM32Cube/Zephyr/MicroPython/ArduPilot/SWUpdate利用、FAT/exFATを読む更新経路、長いfilename処理を棚卸しが必要。CVE-2026-6684はR0.16で修正済み、残りは下流対応待ちが濃い。待つだけは危ない。 #セキュリティ

    Post summary

    The post announces several new CVEs impacting FatFs on embedded USB/SD devices, highlights their high CVSS scores and affected hardware, notes that one has been patched (R0.16), and urges immediate assessment.

    11022627
    6.7K followersView on X
  • ThreatWire@ThreatWire_
    General

    🚨 CVE-2026-6682: The most critical flaw among seven vulnerabilities discovered by @runZeroInc in the widely used FatFs library. Six issues remain unpatched upstream. #CyberSecurity #CVE #Embedded #ThreatWire

    Post summary

    The tweet announces CVE-2026-6682 as a critical flaw in FatFs but provides no additional technical, exploit, or patch information.

    0002095
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Seven flaws in FatFs (CVE-2026-6682 through CVE-2026-6688, CVSS 4.6-7.6) allow memory corruption, crashes, or data leaks via crafted USB/SD media on IoT and embedded devices. Six have no upstream patch. #DFIR_Radar https://t.co/k3ommS1Tah

    Post summary

    Seven FatFs flaws have been disclosed, capable of memory corruption or data leakage through crafted USB/SD media, with six currently lacking upstream patches.

    10000188
    1.7K followersView on X
  • Philips_NE555@Philips_NE555
    False Positive

    CVE-2026-6682 From the C standard, calculations with unsigned integer operands can never overflow nor get undefined. Some processor or imprementation might rise an exception.

    Post summary

    The message argues that CVE‑2026‑6682 is likely a false positive because unsigned arithmetic per the C standard cannot overflow, implying the vulnerability may not exist.

    10000245
    2.4K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-6682: FatFs FAT32 Integer Overflow - What It Means for Your Business and How to Respond https://hubs.li/Q04r-Lyf0

    Post summary

    The article announces CVE‑2026‑6682, a FatFs FAT32 integer overflow, and discusses its implications for businesses and recommended response actions.

    0000043
    32 followersView on X
  • Timothy E. Perdue@TimothyperdueE
    Patch

    FatFs is everywhere (USB, SD, firmware), and @runZeroInc just dropped 7 vulnerabilities. Worse? 6 have NO upstream fix, forcing vendors to DIY patch. The nastiest is CVE-2026-6682. This is a supply chain mess waiting to happen. Patch your firmware.

    Post summary

    RunZeroInc announced seven FatFs vulnerabilities, including CVE-2026-6682, noting that most lack upstream fixes and recommending vendors patch or DIY fix the firmware.

    00000224
    7.9K followersView on X
  • Bryan@so_sthbryan
    Disclosure

    A USB stick can jailbreak an embedded device. Seven unpatched CVEs hit FatFs, the FAT library shipped in millions of firmwares: - Affects ESP-IDF, STM32Cube, Zephyr, ArduPilot - Top bug CVE-2026-6682 scores CVSS 7.6 via crafted FAT images If your firmware reads SD cards, audit this now. https://github.com/runZeroInc/vulns-2026-fatfs-chance

    Post summary

    The post discloses seven unpatched FatFs CVEs, including a top‑scoring issue, highlights how they can be exploited via crafted FAT images on a USB stick, and points to a GitHub repo that likely contains a PoC.

    0000084
    155 followersView on X
  • SecureChap@SecureChap
    Disclosure

    FatFs, the FAT12/16/32 and exFAT driver inside millions of cameras, drones, and crypto wallets, carried seven CVEs. runZero disclosed CVE-2026-6682 through CVE-2026-6688 on July 1, 2026 after contacting the single maintainer and JPCERT/CC with no upstream fix for six of them. Only CVE-2026-6684, a GPT partition DoS, was patched in R0.16. CVE-2026-6682 lets an attacker-controlled file size from FAT32 mount arithmetic become a read length, producing memory corruption. CVE-2026-6687 overflows the stack via an uncapped exFAT volume-label length. CVE-2026-6688 hits fixed buffers in downstream wrappers that copy long filenames with strcpy or undersized sprintf calls. A malformed disk image delivered by USB, SD card, or OTA update is enough. Espressif ESP-IDF, STM32Cube, Zephyr, MicroPython, and ArduPilot are among the platforms that ship it. Memory-constrained targets lack ASLR or any memory protection. The bugs survived a 2017 manual audit. In March 2026 they reappeared when Visual Studio Code with GitHub Copilot drove a basic fuzzer. PoCs and disk images are at http://github.com/runZeroInc/vulns-2026-fatfs-chance. One developer's filesystem quietly became the storage layer for entire classes of connected hardware.

    Post summary

    runZero disclosed seven CVEs in FatFs drivers, providing PoCs and technical details; one CVE has received a patch while no active exploitation is reported.

    0000084
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelm-chanfatfs---

Explore more