Security bulletin 2026-07#
This bulletin lists the critical and high severity vulnerabilities that were fixed for the month of July, 2026.
This bulletin was last updated on July 30th, 2026.
Vulnerability details#
CVE |
Reference |
Impact |
Modules affected |
Fixed by |
|---|---|---|---|---|
TBD |
b/512562473 |
S |
pw_protobuf |
ed4e552afe0093c8c70218392a07af77ab6668fd |
TBD |
b/512562483 |
DoS |
pw_transfer |
7c29e52c8b99a8792b7e44f6687930c311f4f78f |
How to interpret the table#
CVEs are assigned after a fix is released, and may be listed as “TBD” in the interim.
If the ‘Reference’ column is “N/A”, the bug report cannot be made public at this time.
The ‘Impact’ column uses the following abbreviations:
Abbreviation
Definition
CE
Potential code execution, including most memory corruptions that affect control flow.
S
Spoofing, such as injection of malicious data from what appears to be a valid source
T
Tampering, such as modifying state or user data in way that affects device behavior
ID
Information disclosure, including memory corruptions such as out-of-bound reads
DoS
Denial of service, such as triggering assertions
N/A
Classification not available
The ‘Fixed by’ column provides the revision that consumers should upgrade to or cherry-pick.
The ‘Modules affected’ column lists the primary modules affected. Be aware that other modules may be affected through transitive dependencies.