Nordic Semiconductor ASA has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- nRF Connect SDK 1
- nRF5340 1
- nRF54H20 1
Worst active — by depth score
CVE-2026-14297High· 8.7A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory…48CVE-2026-14296High· 7.5When using the Direct XIP update strategy, the main application image starts other cores (i.e41CVE-2026-18796Medium· 6.8Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code37
Nordic Semiconductor ASA vulnerabilities
CVEs affecting Nordic Semiconductor ASA, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-18796Medium· 6.8Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root c…
CVE-2026-14297High· 8.7A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory…
A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory…
CVE-2026-14296High· 7.5When using the Direct XIP update strategy, the main application image starts other cores (i.e
When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that…