HIGH
Nordic Semiconductor ASA
CVE published 2026-09-07
CVE-2026-14296
PatchSiren debrief for CVE-2026-14296: when using the Direct XIP update strategy, MCUboot in bare configuration may pick different slots for main application and radio image, leading to unauthenticated radio image boot. This occurs because MCUboot assumes a system is bootable if at least one slot for each image is available. The main application image starts other cores, such as the radio core, based on t [truncated]