2026.07.17

Product Update Notification - Firmware Vulnerability Scanning in nRF Cloud

You can now upload an SBOM to nRF Cloud, and it will scan it against public vulnerability databases, listing any CVEs found along with their severity. It also includes tools to triage and manage each CVE, and if you have devices connected to nRF Cloud, you can see how many devices are currently running an impacted software version.

You don't need to integrate a device to try it out; simply create an account, navigate to Security Services, upload an SBOM, and nRF Cloud will highlight CVEs present in the SBOM.

 

Combined with nRF Cloud's existing firmware OTA capabilities, you can go from identifying a vulnerability to patching it and monitoring the rollout, in one place.

 

Availability:

  • Developer plan: SBOM upload and scanning, free, no integration required.
  • Pro plan: free trial of Security Services package available now, including CVE details, triage management and device exposure analysis. 

You can learn more here, watch the webinar on demand, or go straight to nRF Cloud and upload your first SBOM to get started - no integration required.