CVE-2026-6688Disclosure(elm-chan / fatfs)

MEDIUMCVSS 7.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch elm-chan fatfs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling. With LFN enabled, fno.fname can be up to 255 characters; many callers copy it into short fixed buffers without bounds checks, causing overflow. This maps to CWE-120 (Buffer Copy without Checking Size of Input). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fatfs

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-04); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
fatfs

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-07-04: 2Mentions · 2026-07-06: 1Mentions · 2026-07-07: 2PoC Mentioned / Linked · 2026-07-04: 2PoC Mentioned / Linked · 2026-07-07: 1Exploit Tool / Code · 2026-07-07: 1Patch / Workaround · 2026-07-04: 2Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-04: 2Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 207-0407-0607-07
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-042
Disclosure2
2026-07-061
General1
2026-07-072
Disclosure1General1
Full discourse5 posts
  • Mr. OS@ksg93rd
    General

    #AppSec #Threat_Research 1⃣ Veeam Backup Authenticated RCE Explained https://blog.securelayer7.net/cve-2026-44963-veeam-backup-authenticated-rce-binaryformatter-bypass // CVE-2026-44963 2⃣ Multiple LPE Vulnerabilities in Little Orbit GFAC Driver (GFAC_Sys_x64.sys) https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168 3⃣ Seven FatFs bugs, one very large blast radius https://www.runzero.com/blog/fatfs-bugs // CVE-2026-6682 - CVE-2026-6688 + PoCs https://github.com/runZeroInc/vulns-2026-fatfs-chance http://www.cyberpocket.org

    Post summary

    The post catalogs several CVEs with links to discussion posts and code repos, offering proof‑of‑concepts and technical details, but without evidence of active exploitation or patches.

    0701661.1K
    3.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Siber güvenlik şirketi runZero tarafından, yaygın olarak kullanılan FatFs dosya sistemi kütüphanesinde 7 güvenlik açığı tespit edildi. Güvenlik kameraları, IoT cihazları, dronlar ve birçok gömülü sistem potansiyel olarak etkilenebilir. En kritik açık CVE-2026-6682 (CVSS 7.6), özel hazırlanmış FAT32/exFAT medya üzerinden bellek bozulmasına (memory corruption) ve bazı senaryolarda uzaktan kod çalıştırmaya (RCE) yol açabiliyor. Tespit edilen CVE'ler: • CVE-2026-6682 – Integer overflow → Memory corruption / RCE • CVE-2026-6683 – exFAT divide-by-zero (DoS) • CVE-2026-6684 – Bozuk GPT partition tablosu ile DoS • CVE-2026-6685 – Cache hesaplama hatası, veri bozulması • CVE-2026-6686 – Bilgi sızıntısı • CVE-2026-6687 – exFAT volume label buffer overflow • CVE-2026-6688 – Long File Name (LFN) buffer overflow Şu ana kadar aktif istismar raporlanmadı. Ancak PoC'ler genele açık durumda. FAT/FAT32/exFAT kullanan gömülü sistem geliştiren üreticilerin FatFs entegrasyonlarını gözden geçirerek gerekli güvenlik güncellemelerini yayınlaması önem taşıyor.

    Post summary

    RunZero alerts on seven new CVEs in FatFs, including CVE‑2026‑6682 that can lead to RCE, with publicly available PoCs but no reported active exploitation; vendors are urged to review and patch their integrations.

    01072828
    2.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Seven flaws in FatFs (CVE-2026-6682 through CVE-2026-6688, CVSS 4.6-7.6) allow memory corruption, crashes, or data leaks via crafted USB/SD media on IoT and embedded devices. Six have no upstream patch. #DFIR_Radar https://t.co/k3ommS1Tah

    Post summary

    The tweet announces seven memory-corruption flaws in FatFs, providing CVSS scores and impact details, and notes that six of them lack an upstream patch.

    10000188
    1.7K followersView on X
  • Philips_NE555@Philips_NE555
    General

    CVE-2026-6688 File name can reach 255 characters in length. Please check if the size of file name buffer is sufficient.

    Post summary

    The note references CVE-2026-6688 and highlights the 255‑character file name length issue, but it provides no actionable insights, exploit code, patch information, or evidence of active use.

    10000131
    2.4K followersView on X
  • SecureChap@SecureChap
    Disclosure

    FatFs, the FAT12/16/32 and exFAT driver inside millions of cameras, drones, and crypto wallets, carried seven CVEs. runZero disclosed CVE-2026-6682 through CVE-2026-6688 on July 1, 2026 after contacting the single maintainer and JPCERT/CC with no upstream fix for six of them. Only CVE-2026-6684, a GPT partition DoS, was patched in R0.16. CVE-2026-6682 lets an attacker-controlled file size from FAT32 mount arithmetic become a read length, producing memory corruption. CVE-2026-6687 overflows the stack via an uncapped exFAT volume-label length. CVE-2026-6688 hits fixed buffers in downstream wrappers that copy long filenames with strcpy or undersized sprintf calls. A malformed disk image delivered by USB, SD card, or OTA update is enough. Espressif ESP-IDF, STM32Cube, Zephyr, MicroPython, and ArduPilot are among the platforms that ship it. Memory-constrained targets lack ASLR or any memory protection. The bugs survived a 2017 manual audit. In March 2026 they reappeared when Visual Studio Code with GitHub Copilot drove a basic fuzzer. PoCs and disk images are at http://github.com/runZeroInc/vulns-2026-fatfs-chance. One developer's filesystem quietly became the storage layer for entire classes of connected hardware.

    Post summary

    runZero publicly disclosed seven FatFs CVEs, supplied PoCs and disk images on GitHub, noted a single patch, and detailed several memory corruption vulnerabilities.

    0000084
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelm-chanfatfs---

Explore more