ThreatCluster

Two New Vulnerabilities Discovered in TPM 2.0 Reference Implementation

First seen 11 Aug 2026, 18:27 UTC Api.Msrc.Microsoft 81% similarity 58

Article Content

Browse articles
ThreatCluster

On August 11, 2026, two vulnerabilities were published affecting the TPM 2.0 reference implementation. CVE-2026-6726 is a spoofing vulnerability due to improper object-slot reuse, while CVE-2026-6727 is an information disclosure vulnerability linked to RSA OAEP timing side channels. Both vulnerabilities were assigned by MITRE on behalf of the Trusted Computing Group and impact Microsoft Windows systems. These vulnerabilities could potentially allow attackers to exploit the TPM 2.0 implementation, leading to unauthorized access or data leakage. Microsoft has released updates to address these vulnerabilities. Security professionals are advised to review the updates and apply necessary patches.

Key Points: • CVE-2026-6726 involves a spoofing vulnerability in TPM 2.0. • CVE-2026-6727 is an information disclosure vulnerability related to RSA OAEP timing. • Both vulnerabilities were published on August 11, 2026, and affect Microsoft Windows.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-6726 published
MITRE assigned CVE-2026-6726 for a spoofing vulnerability in TPM 2.0 due to improper object-slot reuse.
Api.Msrc.Microsoft
2026-08-11
CVE-2026-6727 published
MITRE assigned CVE-2026-6727 for an information disclosure vulnerability in TPM 2.0 involving RSA OAEP timing.
Api.Msrc.Microsoft
2026-08-11
Microsoft releases updates
Microsoft incorporated updates to Windows to address both CVE-2026-6726 and CVE-2026-6727 vulnerabilities.
Api.Msrc.Microsoft

Community

Browse all →

Tracked Entities in This Story