What is CVE-2026-0849?
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack execution.
Timeline
- 2026-03-16Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Zephyrproject Zephyr
Remediation Steps
- Verify all Pharos Mosaic Show Controller installations in use
- Apply Pharos security firmware update patching unauthenticated command execution
- Isolate Mosaic controllers on separate VLAN with restricted network access
- Change default credentials and implement strong authentication mechanisms
- Monitor Mosaic controller logs for unusual command execution activities
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 5 of March 2026 (March 30 – April 5)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.