HP ThinPro Vulnerability Exposes Disk Encryption to Physical Attacks

HP ThinPro Vulnerability Exposes Disk Encryption to Physical Attacks

First seen 11 Aug 2026, 20:12 UTC GbhackersScworld 91% similarity 67.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability in HP ThinPro 8 and 9 allows attackers with physical access to bypass TPM-backed full-disk encryption. Discovered by researcher Darren McDonald in early 2026, the flaw enables attackers to modify the initramfs script, leading to the recovery of the LUKS encryption key. This zero-day vulnerability remains unpatched as of August 8, 2026. Affected devices include HP t530 and t540 thin clients. Organizations using ThinPro are advised to enhance security measures, including enabling Secure Boot and setting BIOS passwords. The vulnerability poses significant risks for data protection, especially for devices outside organizational control.

Key Points: • HP ThinPro 8 and 9 have a critical vulnerability allowing bypass of disk encryption. • Attackers can exploit the flaw by modifying the initramfs script with physical access. • Organizations are urged to implement additional security measures to protect sensitive data.

ThreatCluster AI How this analysis works

Timeline

2026-08-08
Vulnerability disclosed by researcher
Darren McDonald revealed a zero-day vulnerability in HP ThinPro that affects disk encryption.
Scworld
2026-08-11
Articles published detailing the vulnerability
Both Scworld and Gbhackers published articles on the vulnerability, highlighting its risks and impact.
Gbhackers

Community

Browse all →

Tracked Entities in This Story