Security Advisories

Security Advisories

Security Advisories (SA) are issued to provide information about known product vulnerabilities.

If you have discovered a potential security vulnerability in a Nordic Semiconductor product or service, please submit a vulnerability report through this form. Learn more about Nordic Semiconductor Vulnerability Disclosure.

SA Title Affected products Version Date
SA-2026-526 Security Advisory v1.0 MQTT CONNACK messages could perform an out of band heap read nRF5 SDK

16.0.0
15.2.0
15.0.0
14.2.0
14.1.0

2026-06-05
SA-2025-479 Security Advisory v1.0 Out-of-bound writes in provisioning module nRF Connect SDK 1.7.1–3.1.x 2026-06-05
SA-2025-447 Security Advisory v1.1 IronSide SE: PROTECTEDMEM vulnerability nRF54H20 IronSide SE v23.0.0+15

IronSide SE v23.0.1+16

2025-11-24
SA-2025-462 Security Advisory v1.0 Robustness against side-channel leakage nRF54 Series All revisions, all packages 2025-12-10
SA-2025-387 Security Advisory v1.0 Effectiveness of nRF54 Series glitch detection system against fault injection (FI) attacks nRF54 Series All revisions, all packages 2025-09-15
SA-2025-380 Security Advisory v1.0 Voltage-based fault injection attack on Arm CryptoCell CC310 AES hardware engine nRF52840 All build codes 2025-04-11
nRF5 SDK v17.1.0
Runtime cryptography library nrf_cc310 ibnrf_cc310_0.9.13
SA-2024-375 Security Advisory v1.0 Matter Protocol - physical attacks against DAC private key nRF52840 nRF52840-CKAA-Dx0

nRF52840-QIAA-Dx0

2024-11-15
SA-2023-234 Security Advisory v1.1 Unauthorized Thread network key update nRF52811 All build codes 2023-07-06
nRF52833 All build codes
nRF52840 All build codes
nRF5340 All build codes
Thingy:53 All build codes
nRF5 SDK for Thread & Zigbee 4.2.0 and earlier
nRF Connect SDK 2.4.0 and earlier
Thread Border Router Reference

A892bf7 -> docker image and earlier
A892bf7 -> source recommendation

Thread Certification Reference Dongle

20230119-ce1647697 and earlier for Thread 1.3
20221027-d5a53efde and earlier for Thread 1.2
20200818 and earlier for Thread 1.1

Thread Certification Reference Border Router

1.3-20230119 + 20230119-ce1647697 and earlier for Thread 1.3
20221027+20221027-d5a53efde and earlier for Thread 1.2

Thingy:53 pre-compiled firmware – Matter and HomeKit 2023-03-24 release and earlier
IN133 Informational Notice v2.0 A fault injection technique of logical access port protection mechanisms nRF52805 nRF52805-CAAA-Ax0 2025-06-24
nRF52810

nRF52810-CAAA-up to and including Dx0

nRF52810-QCAA-up to and including Dx0

nRF52810-QFAA-up to and including Dx0

nRF52811

nRF52811-CAAA-Ax0

nRF52811-QCAA-Ax0

nRF52811-QFAA-Ax0

nRF52820 nRF52820-QDAA-up to and including Cx0
nRF52832

nRF52832-CIAA-up to and including Ex0

nRF52832-QFAA-up to and including Ex0

nRF52832-QFAB-up to and including Ex0

nRF52833

nRF52833-CJAA-Ax0

nRF52833-QDAA-Ax0

nRF52833-QIAA-Ax0

nRF52840

nRF52840-CKAA-up to and including Dx0

nRF52840-QFAA-up to and including Dx0

nRF52840-QIAA-up to and including Dx0

IN119 Informational Notice Security Vulnerability v1.0 nRF51 Bluetooth® Low Energy stack buffer overrun vulnerability

Bluetooth Low Energy SoftDevices

Released before July 2016 2019-08-12