CVE-2026-97686 MEDIUM

CVE-2026-97686: VxWorks 7 Memory Resource leak

Vendor Wind River
Product VxWorks 7
Weakness CWE-772
Published September 28, 2026
Last update September 28, 2026

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.

Key dates

02Disclosure timeline

September 28, 2026 CVE published
September 28, 2026 Record updated