CVE-2026-6686Disclosure(elm-chan / fatfs)

MEDIUMCVSS 4.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch elm-chan fatfs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fatfs

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fatfs

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-04: 1Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-07-04: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-07-04: 107-0407-06
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Classification over time
DateTotalLabels
2026-07-041
Disclosure1
2026-07-061
General1
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Siber güvenlik şirketi runZero tarafından, yaygın olarak kullanılan FatFs dosya sistemi kütüphanesinde 7 güvenlik açığı tespit edildi. Güvenlik kameraları, IoT cihazları, dronlar ve birçok gömülü sistem potansiyel olarak etkilenebilir. En kritik açık CVE-2026-6682 (CVSS 7.6), özel hazırlanmış FAT32/exFAT medya üzerinden bellek bozulmasına (memory corruption) ve bazı senaryolarda uzaktan kod çalıştırmaya (RCE) yol açabiliyor. Tespit edilen CVE'ler: • CVE-2026-6682 – Integer overflow → Memory corruption / RCE • CVE-2026-6683 – exFAT divide-by-zero (DoS) • CVE-2026-6684 – Bozuk GPT partition tablosu ile DoS • CVE-2026-6685 – Cache hesaplama hatası, veri bozulması • CVE-2026-6686 – Bilgi sızıntısı • CVE-2026-6687 – exFAT volume label buffer overflow • CVE-2026-6688 – Long File Name (LFN) buffer overflow Şu ana kadar aktif istismar raporlanmadı. Ancak PoC'ler genele açık durumda. FAT/FAT32/exFAT kullanan gömülü sistem geliştiren üreticilerin FatFs entegrasyonlarını gözden geçirerek gerekli güvenlik güncellemelerini yayınlaması önem taşıyor.

    Post summary

    runZero has announced seven FatFs vulnerabilities, released PoCs, but no active exploitation has been observed. Vendors are urged to review and implement updates.

    01072828
    2.2K followersView on X
  • Philips_NE555@Philips_NE555
    General

    CVE-2026-6686 As described in the manual.

    Post summary

    The text only cites the CVE identifier with no additional details or actionable information.

    10000187
    2.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelm-chanfatfs---

Explore more