OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102709

HIGH · CVSS 8.4 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Multiple TrustZone-M non-secure callable entry functions are vulnerable due to improper validation of non-secure pointers, allowing attackers in the non-secure environment to manipulate pointers to secure memory. This flaw can lead to unintended disclosure of sensitive information, including cryptographic materials, compromising the integrity of secure operations. Organizations utilizing TrustZone-M technology should prioritize addressing this vulnerability to maintain the confidentiality and security of their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102709
Severity
HIGH
CVSS
8.4
EPSS
0.10%

Original NVD Description

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.