PatchSiren

Norwegian Cruise Line CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Norwegian Cruise Line CVE published 2026-09-24

CVE-2026-75907

A Norwegian Cruise Line asset's door access control system uses NTAG212 NFC chips with static 7-byte UIDs for authentication, which is insecure because UIDs are sent in the clear and not secret. This allows for easy copying of credentials, as the system only performs identification, not authentication, and lacks challenge-response capabilities. The CVE-2026-75907 vulnerability in Norwegian Cruise Line's d [truncated]