View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical CVE-2026-77234 in FreeRTOS-Kernel timer command handling

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • OWASP Releases Top 10 Security Risks for AI Agent Skills
    OWASP has released a security framework for risks affecting AI agent skills.

    • The framework covers OpenClaw, Claude Code, Cursor, Codex, and VS Code ecosystems.
    • It identifies malicious skills, supply-chain compromise, excessive privileges, insecure metadata, weak isolation, and cross-platform reuse as key risks.
    • Skills are reusable instruction-and-resource bundles that agents can discover, load, and execute with host-agent permissions.
    • A January 2026 ClawHavoc campaign distributed 1,184 malicious skills through 12 publisher accounts linked to one command-and-control address.
      ๐Ÿ“„ Source: owasp.org ยท ๐Ÿ“Ž Coverage: resilientcyber.io ยท ๐Ÿ‘ via Dark Reading
  • google-calendar-url-signing-phishing โ€” r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-77234 โ€” CVSS 9.3 โ€” Improper input validation in FreeRTOS-Kernel timer command handlingImproper i...

  • CVE-2026-62674 โ€” CVSS 9.0 โ€” Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEOmni...

  • CVE-2026-62675 โ€” CVSS 8.8 โ€” Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Ca...

  • CVE-2026-62677 โ€” CVSS 8.8 โ€” Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesy...

  • CVE-2026-41451 โ€” CVSS 8.5 โ€” UAC before 3.3.0 Command Injection via User Substitution in parse_artifact.shUAC (...

  • CVE-2026-41450 โ€” CVSS 8.5 โ€” UAC before 3.3.0 Command Injection via command_collector.shUAC (Unix-like Artifact...

  • CVE-2026-41449 โ€” CVSS 8.5 โ€” UAC before 3.3.0 Command Injection via run_command.shUAC (Unix-like Artifacts Coll...

  • CVE-2026-77236 โ€” CVSS 8.3 โ€” Missing size validation in SecureContext_AllocateContext in FreeRTOS-KernelMi...

  • CVE-2026-77235 โ€” CVSS 8.3 โ€” Missing privilege check in SecureContext_FreeContext in FreeRTOS-KernelMissin...

  • CVE-2026-77237 โ€” CVSS 8.2 โ€” Missing type validation in xQueueAddToSet in FreeRTOS-KernelMissing queue-set...

  • CVE-2026-71862 โ€” CVSS 7.5 โ€” Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showU...

  • CVE-2026-55241 โ€” CVSS 7.5 โ€” Checkmate: Pre-auth Denial of Service via File Upload on RegistrationCheckmat...

  • CVE-2026-62676 โ€” CVSS 7.1 โ€” Omnigent Guardrail policy bypass: shell-command parser fails open in policies...

  • CVE-2026-17252 โ€” CVSS 7.1 โ€” Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based O...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check