Heise.De
Vulnerabilities Found in TPM 2.0 Affecting AMD and Intel Processors
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two vulnerabilities, CVE-2026-6726 and CVE-2026-6727, have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation, affecting many AMD and Intel processors. CVE-2026-6727 allows attackers to exploit timing differences in RSA-OAEP decryption, potentially recovering sensitive information. CVE-2026-6726 enables attackers to bypass key verification, allowing the use of falsified keys. Both vulnerabilities require privileged local access to exploit, making them less concerning for private users but significant for enterprises. The Trusted Computing Group has provided updates, and affected vendors have released firmware and software patches. The vulnerabilities were published on August 11, 2026, and have high CVSS scores of 8.5 and 8.3. Users are advised to apply the updates to mitigate risks.
Key Points: • CVE-2026-6726 and CVE-2026-6727 affect AMD and Intel processors via TPM 2.0. • Exploitation requires privileged local access, limiting risk to private users. • Firmware and software updates have been released to address these vulnerabilities.