Security Advisories (SA) are issued to provide information about known product vulnerabilities.
If you have discovered a potential security vulnerability in a Nordic Semiconductor product or service, please submit a vulnerability report through this form. Learn more about Nordic Semiconductor Vulnerability Disclosure.
| SA | Title | Affected products | Version | Date |
|---|---|---|---|---|
| SA-2026-526 Security Advisory v1.0 | MQTT CONNACK messages could perform an out of band heap read | nRF5 SDK |
16.0.0 |
2026-06-05 |
| SA-2025-479 Security Advisory v1.0 | Out-of-bound writes in provisioning module | nRF Connect SDK | 1.7.1–3.1.x | 2026-06-05 |
| SA-2025-447 Security Advisory v1.1 | IronSide SE: PROTECTEDMEM vulnerability | nRF54H20 | IronSide SE v23.0.0+15 IronSide SE v23.0.1+16 |
2025-11-24 |
| SA-2025-462 Security Advisory v1.0 | Robustness against side-channel leakage | nRF54 Series | All revisions, all packages | 2025-12-10 |
| SA-2025-387 Security Advisory v1.0 | Effectiveness of nRF54 Series glitch detection system against fault injection (FI) attacks | nRF54 Series | All revisions, all packages | 2025-09-15 |
| SA-2025-380 Security Advisory v1.0 | Voltage-based fault injection attack on Arm CryptoCell CC310 AES hardware engine | nRF52840 | All build codes | 2025-04-11 |
| nRF5 SDK | v17.1.0 | |||
| Runtime cryptography library nrf_cc310 | ibnrf_cc310_0.9.13 | |||
| SA-2024-375 Security Advisory v1.0 | Matter Protocol - physical attacks against DAC private key | nRF52840 | nRF52840-CKAA-Dx0 nRF52840-QIAA-Dx0 |
2024-11-15 |
| SA-2023-234 Security Advisory v1.1 | Unauthorized Thread network key update | nRF52811 | All build codes | 2023-07-06 |
| nRF52833 | All build codes | |||
| nRF52840 | All build codes | |||
| nRF5340 | All build codes | |||
| Thingy:53 | All build codes | |||
| nRF5 SDK for Thread & Zigbee | 4.2.0 and earlier | |||
| nRF Connect SDK | 2.4.0 and earlier | |||
| Thread Border Router Reference |
A892bf7 -> docker image and earlier |
|||
| Thread Certification Reference Dongle |
20230119-ce1647697 and earlier for Thread 1.3 |
|||
| Thread Certification Reference Border Router |
1.3-20230119 + 20230119-ce1647697 and earlier for Thread 1.3 |
|||
| Thingy:53 pre-compiled firmware – Matter and HomeKit | 2023-03-24 release and earlier | |||
| IN133 Informational Notice v2.0 | A fault injection technique of logical access port protection mechanisms | nRF52805 | nRF52805-CAAA-Ax0 | 2025-06-24 |
| nRF52810 |
nRF52810-CAAA-up to and including Dx0 nRF52810-QCAA-up to and including Dx0 nRF52810-QFAA-up to and including Dx0 |
|||
| nRF52811 |
nRF52811-CAAA-Ax0 nRF52811-QCAA-Ax0 nRF52811-QFAA-Ax0 |
|||
| nRF52820 | nRF52820-QDAA-up to and including Cx0 | |||
| nRF52832 |
nRF52832-CIAA-up to and including Ex0 nRF52832-QFAA-up to and including Ex0 nRF52832-QFAB-up to and including Ex0 |
|||
| nRF52833 |
nRF52833-CJAA-Ax0 nRF52833-QDAA-Ax0 nRF52833-QIAA-Ax0 |
|||
| nRF52840 |
nRF52840-CKAA-up to and including Dx0 nRF52840-QFAA-up to and including Dx0 nRF52840-QIAA-up to and including Dx0 |
|||
| IN119 Informational Notice Security Vulnerability v1.0 | nRF51 Bluetooth® Low Energy stack buffer overrun vulnerability |
Bluetooth Low Energy SoftDevices |
Released before July 2016 | 2019-08-12 |