CVE-2026-6726Disclosure

LOWCVSS 7.9 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Patch or workaround signal is available
  • 25 mentions across 9 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • General: 7 classified signals
  • Peaked 8d ago at 9 mentions (2026-08-12); latest day: 2
  • 25 total mentions across 9 days

Deep dive

Activity timeline25 mentions / 9d
02579Mentions · 2026-08-12: 9Mentions · 2026-08-13: 3Mentions · 2026-08-14: 4Mentions · 2026-08-15: 2Mentions · 2026-08-16: 1Mentions · 2026-08-17: 2Mentions · 2026-08-25: 1Mentions · 2026-08-27: 1Mentions · 2026-09-20: 2Patch / Workaround · 2026-08-12: 6Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-14: 2Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-12: 4Technical Details · 2026-08-13: 3Technical Details · 2026-08-14: 108-1208-1308-1408-1508-1608-1708-2508-2709-20
Signal classification3 categories
Disclosure
834.8%
Patch
834.8%
General
730.4%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-08-129
Disclosure4Patch5
2026-08-133
Disclosure3
2026-08-144
Disclosure1General2Patch1
2026-08-152
General2
2026-08-161
General1
2026-08-172
General2
2026-08-251
Patch1
2026-08-271
Patch1
Full discourse20 posts
  • Chris Mizo@MizoChris
    Patch

    AMD has confirmed two high-severity TPM vulnerabilities affecting a HUGE range of Ryzen processors! • The flaws are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS scores of 8.5 and 8.3. • AMD says affected firmware TPM implementations could potentially expose TPM-protected data or allow falsified attestation keys, but exploitation requires local access with elevated privileges. • Affected chips include a massive range of Ryzen hardware, from Ryzen 3000 through Ryzen 9000, along with Ryzen AI, Threadripper and other AMD platforms. • AMD actually delivered many of the firmware mitigations back in May, before publicly disclosing the vulnerabilities. • Ryzen 9000 desktop systems are covered by newer ComboAM5PI 1.2.0.3k or 1.3.0.1b firmware. • Ryzen 3000 desktop systems received mitigation through ComboAM4PI 1.0.0.11, while newer AM4 systems use newer ComboAM4v2PI revisions. • AMD recommends checking your motherboard or system manufacturer for the latest BIOS update containing the required firmware. If you’re running a Ryzen system, especially AM4 or AM5, I’d check ASUS, MSI, GIGABYTE or your board maker and make sure you’re on a recent BIOS.

    Post summary

    AMD disclosed two high‑severity TPM flaws and released firmware patches; users must update BIOS to mitigate the risks, with no evidence yet of exploitation.

    172632389718.2K
    3.0K followersView on X
  • JVN 脆弱性レポート@jvnjp
    Disclosure

    [2026/08/12 10:30 公表] TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727) https://jvn.jp/vu/JVNVU96623328/index.html

    Post summary

    The post announces the discovery of two TPM2.0 reference implementation vulnerabilities (CVE‑2026‑6726, CVE‑2026‑6727) without providing PoC, exploit details, patches, or technical specifics.

    031202.3K
    25.5K followersView on X
  • inconnu inconnu@inconnu34283172
    Disclosure

    @Pirat_Nation The vulnerabilities are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS 4.0 scores of 8.5 and 8.3 respectively. AMD says its Firmware TPM implementations are affected. https://videocardz.com/newz/amd-confirms-ryzen-tpm-vulnerabilities-asus-msi-and-gigabyte-already-have-fixes

    Post summary

    AMD confirms two TPM vulnerabilities (CVE-2026-6726, CVE-2026-6727) with CVSS scores 8.5, 8.3, and affected OEMs have released fixes.

    00030164
    83 followersView on X
  • Framebuffer D3lta@framebuffer_br
    Disclosure

    A AMD reconheceu uma vulnerabilidade no Trusted Platform Module (TPM) 2.0, que poderia permitir o acesso não autorizado e a desativação do módulo, impactando CPUs Ryzen da série 3000 a 9000. A falha, identificada como CVE-2026-6726 e ➡️

    Post summary

    AMD disclosed a vulnerability (CVE-2026-6726) affecting TPM 2.0 on Ryzen CPUs that could enable unauthorized access and module disabling, without mentioning patches or evidence of active exploitation.

    10010113
    483 followersView on X
  • JAPAH@japahttv
    Patch

    A AMD confirmou duas falhas altas no fTPM de Ryzen (CVE-2026-6726/6727), corrigidas via BIOS desde maio. Intel reportou o problema. Ryzen AI aguardam correção do Pluton. Fontes: AMD, CERT/CC, TCG e SecurityWeek. https://t.co/yBhOjFOFHa

    Post summary

    AMD confirmed two high‑severity fTPM vulnerabilities in Ryzen (CVE-2026-6726/6727) that have been patched via BIOS updates; Intel reported the issue and Ryzen AI await a Pluton fix.

    0101047
    1.3K followersView on X
  • 乖離(*´∀`)🍑😊🐻😾☔🎵🍢🌸💯🗽🇯🇵🗻🏝️🌲🏡🆓🎮🚗🚴💨@kai_ri_0001

    https://kb.cert.org/vuls/id/431093 CVE-2026-6726 – 改ざんされたTPMキーによる情報漏洩。 CVE-2026-6727 – RSA OAEP復号化におけるタイミングサイドチャネルの脆弱性。

    1000076
    16.5K followersView on X
  • 乖離(*´∀`)🍑😊🐻😾☔🎵🍢🌸💯🗽🇯🇵🗻🏝️🌲🏡🆓🎮🚗🚴💨@kai_ri_0001

    X570 AORUS MASTER (Rev. 1.1/1.2) Checksum: 1E34 Update AM4 AGESA ComboV2 1.2.0.12 Fix AMD TPM Reference Code Errata (CVE-2026-6726, CVE-2026-6727) F40d11.02 MBSep 17, 2026 https://www.gigabyte.com/jp/Motherboard/X570-AORUS-MASTER-rev-11-12/support#Support-Bios

    10000252
    16.5K followersView on X
  • しーにゃ♪@公式@Syynya
    General

    JVNVU#96623328 TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727) https://jvn.jp/vu/JVNVU96623328/index.html ぉ。

    Post summary

    The note simply lists two CVEs associated with the TPM2.0 reference implementation, without any further technical or operational details.

    1000047
    910 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The post mentions two CVEs in the TCG TPM2.0 reference implementation but provides no details on exploits, patches, or technical specifics.

    0001069
    842 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The tweet poses a question about what steps to take if the two TCG TPM2.0 reference implementation vulnerabilities (CVE-2026-6726, CVE-2026-6727) occur, but provides no additional technical details, exploits, or mitigation information.

    0001048
    843 followersView on X
  • Sovereign Kinetic@adomita360
    Disclosure

    AMD-SB-7064: CVE-2026-6726 allows forged TPM attestations; the attestation is valid, and the attested thing is not AMD announced two TPM 2.0 vulnerabilities this week under AMD-SB-7064. One is a timing side-channel issue. The other, which is more serious, has not received enough attention. CVE-2026-6726 allows a local attacker with elevated privileges to trick a certificate authority into issuing credentials for a tampered TPM key. The attacker can then use these credentials to forge attestations. The attestation appears valid, but what it claims to prove is not. Many AI governance systems rely on attestation as a foundation. They require proof that the platform is healthy before trusting its reports. Attestation is just a statement a machine makes about itself, signed with its own key. If an attacker can forge that key, all systems that depend on it are affected, and the logs will not show any problems. This is not a criticism of attestation itself. It is a useful control, and both CVEs have fixes. Both attacks also require local elevated privileges. The real issue is where to keep records of physical actions. If a robot moves, a breaker closes, or a pump runs, the evidence should not come from the system whose trustworthiness is in doubt. Instead, it should be recorded separately, using hardware that the main system cannot access or change. This approach is used in a patented architecture in which Sovereign Kinetic filed, tying authorization to the energy path and keeping the record of what was authorized versus what actually happened separate from the main system. While it does not detect software compromise and would not have caught this specific bug, it ensures that the physical record does not depend on what the software claims. #ArtificialIntelligence #AIGovernance #CriticalInfrastructure #Semiconductors #Robotics #AI #HardwareSecurity #RootOfTrust #TrustedComputing #RemoteAttestation #ConfidentialComputing #FirmwareSecurity #TPM #OTSecurity #PhysicalAI #AgenticAI #FunctionalSafety #ZeroTrust https://lnkd.in/ey4biEyk

    Post summary

    AMD announced CVE-2026-6726 under AMD-SB-7064 as a local privilege escalation that allows forging of TPM attestations, posing a risk to attestation-based systems, with patches already available.

    0001053
    187 followersView on X
  • Human Firewall@HumanFirewallHQ
    Disclosure

    Two TPM 2.0 reference-implementation bugs also closed: CVE-2026-6726 (spoofing) and CVE-2026-6727 (timing side-channel). The wrinkle: Windows Update alone can't fully fix them — your OEM's firmware has to. That part is a slower calendar than a KB article.

    Post summary

    Two TPM 2.0 reference‑implementation bugs, CVE‑2026‑6726 (spoofing) and CVE‑2026‑6727 (timing side‑channel), have been closed, but OEM firmware updates—not just Windows Update—are needed to address them.

    1000048
    2 followersView on X
  • inconnu inconnu@inconnu34283172
    Patch

    @pin123345 @Pirat_Nation The vulnerabilities are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS 4.0 scores of 8.5 and 8.3 respectively. AMD says its Firmware TPM implementations are affected. https://videocardz.com/newz/amd-confirms-ryzen-tpm-vulnerabilities-asus-msi-and-gigabyte-already-have-fixes

    Post summary

    AMD’s TPM firmware vulnerabilities CVE-2026-6726 and CVE-2026-6727 are confirmed with high CVSS scores, and affected vendors have already released fixes.

    1000061
    83 followersView on X
  • くろがねッと☆@kuroganet39
    Patch

    ASUS PRIME A520M-K PRIME A520M-E バージョン 3644 15.97 MB 2026/08/27 "1. Update AGESA version to ComboV2 PI 1.2.0.12. 2. Mitigate fTPM vulnerabilities (CVE-2026-6726, CVE-2026-6727)."

    Post summary

    The text provides an AGESA firmware update and mitigation instructions for the fTPM vulnerabilities CVE-2026-6726 and CVE-2026-6727 on ASUS PRIME A520M boards.

    0000091
    1.2K followersView on X
  • ソニーショップ ナカムラ電器@sshopnakamura
    Patch

    【VAIOユーザーは確認を💻】 VAIO S15・S13・S11・A12向けに、最新アップデートが公開されました。 今回は単なる動作改善だけではありません。 🔹VAIO S15:BIOS更新で安定性向上 🔹Intel ME Firmware更新 🔹CVE-2026-6726/6727の脆弱性に対応 対象モデルを長く使っている方は、現在のバージョンを確認しておきましょう。 👇対象機種・アップデート内容をまとめました https://nakamura.yokohama/2026-08-25-vaio-update-158244.html #VAIO #VAIOS15 #VAIOアップデート

    Post summary

    VAIO released BIOS and Intel ME firmware updates that address CVE‑2026‑6726/6727, with a link to detailed update information for affected models.

    00000182
    833 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post references two CVEs in the TCG TPM 2.0 reference implementation but provides no technical details, PoC, exploit code, patches, or evidence of active exploitation.

    0000059
    842 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post briefly outlines a three‑axis analysis of CVE‑2026‑6726 and CVE‑2026‑6727 but provides no technical details, exploit code, or mitigation information.

    0000072
    843 followersView on X
  • Stefan Klatt@TheUnicornXXL
    Patch

    AMD schließt TPM-Lücken bei zahlreichen Ryzen-CPUs https://www.connect.de/news/amd-ryzen-tpm-sicherheitsluecke-cve-2026-6726-cve-2026-6727-mainboard-firmware-updates-3213117.html

    Post summary

    AMD has issued firmware updates to close two TPM-related vulnerabilities (CVE‑2026‑6726 and CVE‑2026‑6727) affecting many Ryzen CPUs; no active exploitation or PoC is reported.

    0000066
    1.4K followersView on X
  • ゆぅさん@YY20424277
    General

    「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The post simply lists two CVE identifiers for a TPM2.0 reference implementation and suggests a concise write‑up, without any technical, exploit, or mitigation details.

    0000054
    843 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The tweet poses a hypothetical question about initial response steps for two new TPM2.0 reference implementation vulnerabilities but provides no further technical, exploit, or mitigation details.

    0000065
    843 followersView on X

Explore more