www.amd.com
AMD Confirms High-Severity TPM Vulnerabilities in Ryzen Processors
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
AMD has reported two high-severity vulnerabilities in its Trusted Platform Module (TPM) 2.0 implementation, affecting Ryzen processors. The vulnerabilities, identified as CVE-2026-6726 and CVE-2026-6727, have CVSS scores of 8.5 and 8.3, respectively. They can be exploited by sending malicious commands to the TPM from user-mode applications, potentially allowing attackers to read sensitive data or disrupt TPM availability. Affected systems include AMD Ryzen 3000-9000 series desktop CPUs, various Ryzen mobile CPUs, and Threadripper series CPUs. Firmware updates have been provided to motherboard manufacturers to mitigate these vulnerabilities, and users are advised to update their BIOS. The vulnerabilities were discovered by Intel security researchers and reported to the Trusted Computing Group (TCG). The nature of the attacks requires local system access with elevated privileges, limiting their exploitability. AMD has stated that these vulnerabilities were identified before any exploitation occurred.
Key Points: • Two high-severity TPM vulnerabilities in AMD Ryzen processors have been confirmed. • CVE-2026-6726 and CVE-2026-6727 have CVSS scores of 8.5 and 8.3, respectively. • Firmware updates are available, and users should update their BIOS to mitigate risks.