AMD EPYC Embedded 2005 CPU  Image © AMDAMD EPYC Embedded 2005 CPU (Image © AMD)

The vulnerabilities are caused by an out-of-bounds read error triggered when malicious commands are sent to a TPM 2.0 module using the affected reference code.

Technical Details on CVE-2026-6726 and CVE-2026-6727

Two significant vulnerabilities have been documented, both of which have been rated “high.”

CVE-2026-6726 is an information disclosure vulnerability with a CVSS score of 8.5. This vulnerability allows a local attacker with elevated privileges to obtain credentials from a TPM-enabled certification authority. Once these credentials are stolen, the attacker can create forged TPM keys—such as attestation keys or TLS authentication keys—to forge TPM 2.0 attestations.

CVE-2026-6727 is a timing side-channel vulnerability in RSA-OAEP decryption with a CVSS score of 8.3. This vulnerability allows an attacker with elevated privileges to decrypt ciphertexts, including session salts and login blobs, that were encrypted with the RSA endorsement key. It can also be used to forge TPM 2.0 attestation keys.

Affected Hardware and Processors

The vulnerability affects a wide range of AMD processor families. Affected product lines include:

  • EPYC Series: Including the 4004 and 4005 series, as well as the EPYC embedded models 2005 and 4005.
  • Ryzen Embedded: Various generations, including the 5000, 7000, 8000, 9000, P100, R1000, R2000, V1000, V2000, and V3000 series.
  • Ryzen Desktop and Mobile: A wide range from the Ryzen 3000 series to the newer Ryzen AI 300 and 400 series.
  • Other series: Athlon 3000 Mobile processors and Ryzen Threadripper (including the PRO and 7000 series).

Mitigations and Firmware Updates

To address these issues, AMD has provided updated Platform Initialization (PI) firmware to original equipment manufacturers (OEMs). Since the TPM is integrated into the system firmware, users cannot apply these fixes directly. Instead, they must obtain a BIOS update from their respective hardware manufacturers.

The release dates for these fixes began in May 2026 and extended through July 2026 for most product lines. Updates for the latest Ryzen AI series are scheduled for August 2026 to address Pluton-based implementations. These vulnerabilities were originally reported to the TCG by researchers at Intel.