we_are_coded.by CODE · The world, decoded
БГ
FatFs

Seven holes in FatFs threaten millions of embedded devices, and there's no full patch

runZeroSecurity

runZero disclosed 7 vulnerabilities at once in the FatFs file system - embedded in drones, cameras, hardware wallets, and dozens of platforms. Only one has been patched. For the rest, there's no fix yet.

In short
  • runZero disclosed 7 vulnerabilities (CVE-2026-6682..6688, CVSS 4.6-7.6) in FatFs.
  • Embedded in ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot - drones, cameras, hardware wallets.
  • Only 1 has been patched (R0.16); no fix for the rest; PoC published; no real-world attacks so far.
Checked on5 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Researchers at runZero (a cybersecurity firm) disclose seven flaws in FatFs - a lightweight FAT/exFAT file system embedded in the invisible layer of millions of devices. With a component like this, the problem is scope - one hole repeats everywhere it's embedded.

The facts: the seven vulnerabilities carry the identifiers CVE-2026-6682 through CVE-2026-6688, with CVSS scores from 4.6 to 7.6. FatFs is embedded in ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot, and from there - in drones, cameras, and hardware crypto wallets. Only one hole (CVE-2026-6684) has been patched upstream in version R0.16; for the rest, there's no fix yet. runZero published proof-of-concept disk images (PoC). So far, there's no data on real-world attacks.

There's one detail that weighs more than the score of any single hole - where the code lives. Software that nobody sees and almost nobody updates is exactly where an old vulnerability sits for years. The device works, so it looks fine. And inside, nothing has been patched.

Security of embedded things is a debt we pay off slowly. A hole in a server gets plugged in days. The same hole in a camera or drone you keep at home stays there until you replace the device. 'No attacks yet' isn't reassurance here - it's the window.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Sources
Official primary source
→runZero - FatFs vulnerabilities
Media confirmation
→Cyber Security News - FatFs vulnerabilities
Original: https://wearecoded.com/en/articles/fatfs-embedded-vulnerabilities.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news