PatchSiren

Nordic Semiconductor ASA CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Nordic Semiconductor ASA CVE published 2026-09-07

CVE-2026-14296

PatchSiren debrief for CVE-2026-14296: when using the Direct XIP update strategy, MCUboot in bare configuration may pick different slots for main application and radio image, leading to unauthenticated radio image boot. This occurs because MCUboot assumes a system is bootable if at least one slot for each image is available. The main application image starts other cores, such as the radio core, based on t [truncated]