CVE-2026-18796
QSPI flash encryption side-channel leakage
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
| CWE | CWE-1342 |
| Vendor | nordic semiconductor asa |
| Product | nrf5340 |
| Published | Sep 7, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for nordic semiconductor asa nrf5340
Be the first to know when new unknown vulnerabilities affecting nordic semiconductor asa nrf5340 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Nordic Semiconductor ASA / nRF5340
All build codes
References
Credits
🔍 Reported externally through PSIRT by Daniël Eijkman and Damian Vizár (CSEM)