diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml
index 325816ca7d..2fb8874543 100644
--- a/doc/arm/notes.xml
+++ b/doc/arm/notes.xml
@@ -76,6 +76,16 @@
+
+
+
+
+ It was possible to trigger a assertion when rendering a
+ message using a specially crafted request. This flaw is
+ disclosed in CVE-2016-2776. [RT #43139]
+
+
+