FreeRTOS, the open-source operating system that powers most of the small microprocessors and microcontrollers in many IoT hardware products has newly identified vulnerabilities.
The vulnerabilities are in the TCP/IP stack and affect the FreeRTOS.
The versions affected
The versions affected are FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), AWS FreeRTOS up to V1.3.1, OpenRTOS and SafeRTOS (With WHIS Connect middleware TCP/IP components).
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for the product, threat, and vendor moves that mattered after this guide was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why this is a disaster
FreeRTOS is used in many IoT devices. These devices are often inexpensive and not easily patched. In fact, many of these devices have firmware that has not been updated for many years.
Examples of products that use FreeRTOS are fitness trackers, temperature monitors, appliances, car, door locks, water meters, and many more small devices. The vulnerable devices that use the TCP/IP are the vulnerable ones. This means that the devices can connect to the internet.
Since we know that these devices are connected we can conclude that they can also be patched.
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for the new exploitation, policy moves, and risk shifts this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
But will they?
Likely not. So this is a vulnerability that has the potential to be exploited for years to come.
The full list of the vulnerabilities, and their identifiers, that affect FreeRTOS:
| CVE-2018-16522 | Remote Code Execution |
| CVE-2018-16525 | Remote Code Execution |
| CVE-2018-16526 | Remote Code Execution |
| CVE-2018-16528 | Remote Code Execution |
| CVE-2018-16523 | Denial of Service |
| CVE-2018-16524 | Information Leak |
| CVE-2018-16527 | Information Leak |
| CVE-2018-16599 | Information Leak |
| CVE-2018-16600 | Information Leak |
| CVE-2018-16601 | Information Leak |
| CVE-2018-16602 | Information Leak |
| CVE-2018-16603 | Information Leak |
| CVE-2018-16598 | Other |
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Cyber Threat Hunting – A Complete Guide
Cyber threat hunting is the process of proactively hunting for attackers or malware that are lurking in your network system and may...
Best Vulnerability Management Tools in 2026: What Security Teams Should Compare
A practical buyer guide to the best vulnerability management tools in 2026, including what to compare, which workflows matter most, and how...
Why is Cybersecurity Important in 2026?
Why cybersecurity matters in 2026 for business continuity, customer trust, legal exposure, resilience, and operational stability.
The 5-Minute Cyber Brief: September 1, 2026
The fastest way to catch up on what changed after this article was published.