HeadlinesBriefing favicon HeadlinesBriefing.com

AMD Acknowledges TPM Vulnerability, Patched

TechPowerUp News •
×

AMD has acknowledged a new TPM vulnerability that was patched before the public announcement. The issue involves a potential out‑of‑bounds read in the TPM 2.0 reference implementation, allowing malicious commands to bypass TPM functionality. Reported as CVE‑2026‑6726 with a CVSS score of 8.5 and CVE‑2026‑6727 with a CVSS of 8.3, the flaw could let attackers disable the TPM and compromise all digital signing and encryption.

Intel security researchers identified the problem and reported it to the Trusted Computing Group (TCG) and its Vulnerability Response Team (VRT). AMD is collaborating with motherboard vendors to ship updates. Patches have been distributed since May, with additional releases in June and July. The only CPUs awaiting the August update are the Ryzen AI 300 series, Ryzen AI 400 desktop and notebook series, and the Ryzen AI Max 300 series, which will receive Pluton secure‑processor updates this month.

The coordination between Intel researchers, TCG, and AMD ensured a timely response, preventing attackers from gaining escalated privileges and compromising security enclaves. This incident underscores the importance of keeping motherboard firmware current. Check your system’s firmware and apply the latest updates to maintain security.