runZero disclosed 7 vulnerabilities at once in the FatFs file system - embedded in drones, cameras, hardware wallets, and dozens of platforms. Only one has been patched. For the rest, there's no fix yet.
- runZero disclosed 7 vulnerabilities (CVE-2026-6682..6688, CVSS 4.6-7.6) in FatFs.
- Embedded in ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot - drones, cameras, hardware wallets.
- Only 1 has been patched (R0.16); no fix for the rest; PoC published; no real-world attacks so far.
Researchers at runZero (a cybersecurity firm) disclose seven flaws in FatFs - a lightweight FAT/exFAT file system embedded in the invisible layer of millions of devices. With a component like this, the problem is scope - one hole repeats everywhere it's embedded.
There's one detail that weighs more than the score of any single hole - where the code lives. Software that nobody sees and almost nobody updates is exactly where an old vulnerability sits for years. The device works, so it looks fine. And inside, nothing has been patched.
Security of embedded things is a debt we pay off slowly. A hole in a server gets plugged in days. The same hole in a camera or drone you keep at home stays there until you replace the device. 'No attacks yet' isn't reassurance here - it's the window.