Vulnerabilities Found in TPM 2.0 Affecting AMD and Intel Processors

Vulnerabilities Found in TPM 2.0 Affecting AMD and Intel Processors

First seen 13 Aug 2026, 13:22 UTC Kb.CertHeise.Desecurity-tracker.debian.org 80% similarity 57.8

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2026-6726 and CVE-2026-6727, have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation, affecting many AMD and Intel processors. CVE-2026-6727 allows attackers to exploit timing differences in RSA-OAEP decryption, potentially recovering sensitive information. CVE-2026-6726 enables attackers to bypass key verification, allowing the use of falsified keys. Both vulnerabilities require privileged local access to exploit, making them less concerning for private users but significant for enterprises. The Trusted Computing Group has provided updates, and affected vendors have released firmware and software patches. The vulnerabilities were published on August 11, 2026, and have high CVSS scores of 8.5 and 8.3. Users are advised to apply the updates to mitigate risks.

Key Points: • CVE-2026-6726 and CVE-2026-6727 affect AMD and Intel processors via TPM 2.0. • Exploitation requires privileged local access, limiting risk to private users. • Firmware and software updates have been released to address these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-6726 and CVE-2026-6727 published
Two vulnerabilities in TPM 2.0 were disclosed, affecting AMD and Intel processors with high CVSS scores.
Kb.Cert
2026-08-11
Vulnerabilities reported by Trusted Computing Group
The Trusted Computing Group confirmed the vulnerabilities and provided advisories for affected systems.
Kb.Cert
2026-08-13
Heise reports on TPM vulnerabilities
Heise highlighted the impact of the vulnerabilities on AMD and Intel CPUs, emphasizing the need for updates.
Heise.De
Recent
Firmware updates released
AMD and Intel have distributed firmware updates to manufacturers to address the vulnerabilities.
Heise.De

Community

Browse all →

Tracked Entities in This Story