SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18796

MEDIUM · CVSS 6.8 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Applications utilizing external QSPI flash for encrypted execute-in-place (XIP) on the nRF5340 are vulnerable due to a weakness in the on-the-fly decryption scheme, which compromises the confidentiality and integrity of the stored code. This vulnerability could allow unauthorized access or manipulation of sensitive data. Organizations using affected F5 products should prioritize addressing this issue to mitigate potential security risks.

CVE
CVE-2026-18796
Severity
MEDIUM
CVSS
6.8
EPSS
0.08%
F5

Original NVD Description

Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.