Security Advisories

This page lists all published security advisories for Morse Micro products. Each advisory is identified by a Morse Micro Security Advisory (MM-SA) number and references one or more CVE identifiers.

For information on how to report a vulnerability, see our Security Disclosure Policy.

Customers with active support agreements who require advance notice of advisories under embargo should contact their Morse Micro account team or security@morsemicro.com.

Advisory Feed

An Atom feed of advisories is available at feed.xml for partner security teams to subscribe to.

Published Advisories

Advisory CVE Title Severity Published
MM-SA-2026-001 CVE-2026-7763 Pre-authentication heap buffer overflow in morse.ko TIM IE processing High 4th June 2026
MM-SA-2026-002 CVE-2026-7762 Pre-authentication heap buffer overflow in dot11ah.ko S1G Capabilities IE processing High 4th June 2026
MM-SA-2026-003 CVE-2026-7764 Pre-authentication out-of-bounds read in morse.ko Vendor IE processing Medium 21st May 2026

Naming Convention

Advisory identifiers follow the format MM-SA-YYYY-NNN where YYYY is the year of publication and NNN is a zero-padded sequence number within that year.