🔐 CVE Alert

CVE-2026-18796

UNKNOWN 0.0

QSPI flash encryption side-channel leakage

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.

CWE CWE-1342
Vendor nordic semiconductor asa
Product nrf5340
Published Sep 7, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for nordic semiconductor asa nrf5340

Be the first to know when new unknown vulnerabilities affecting nordic semiconductor asa nrf5340 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Nordic Semiconductor ASA / nRF5340
All build codes

References

NVD ↗ CVE.org ↗ EPSS Data ↗
docs.nordicsemi.com: https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html

Credits

🔍 Reported externally through PSIRT by Daniël Eijkman and Damian Vizár (CSEM)