CVE-2026-87726EPSS p0.7%

CVE-2026-87726CVE-2026-87726

Description

Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem.

Scoring

CVSS 3.9 ()
VectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS0.10% probability of exploitation · percentile 0.7% · 2026-10-10T12:00:23Z
Last modified2026-10-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.