Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere.

A cybersecurity firm has revealed seven security weaknesses in FatFs, a widely deployed filesystem library. FatFs is used by millions of embedded devices to read and write data on FAT and exFAT formatted storage media, such as USB drives and SD cards. The vulnerabilities were disclosed by the security firm runZero.
The flaws, if exploited, could allow an attacker to crash a device or potentially execute arbitrary code. This could lead to denial-of-service conditions or more severe compromise of the affected device. The widespread use of FatFs means that a large number of devices, from consumer electronics to industrial control systems, could be vulnerable.
FatFs is a popular choice for embedded systems due to its small footprint and efficiency, making it suitable for devices with limited resources. Its ability to handle FAT and exFAT file systems makes it a common component for devices that interact with removable storage.
The specific vulnerabilities have not yet been publicly detailed with CVE identifiers, but runZero has indicated that they impact the library's handling of file system operations. The potential for code execution is particularly concerning, as it could enable attackers to gain control over the compromised device.
While the exact number of affected devices is unknown, the pervasive nature of FatFs suggests a broad attack surface. Devices that incorporate this library and are connected to networks or exposed to untrusted storage media are at risk.
Details on the specific technical nature of the vulnerabilities and their exploitability are expected to be released by runZero. Users and manufacturers of embedded devices that utilize FatFs are advised to monitor for updates and security advisories related to the library.
In the absence of specific patches, general security best practices are recommended. This includes limiting exposure of vulnerable devices to untrusted networks and storage media. Regularly updating firmware and software components when patches become available is crucial for mitigating known security risks.
Manufacturers relying on FatFs should investigate their implementations and work with the FatFs maintainers or runZero to understand the scope of the impact and develop remediation strategies. The disclosure highlights the importance of supply chain security, particularly for foundational software components like filesystem libraries that are integrated into a vast array of products.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]