
AMD has confirmed two high-severity TPM vulnerabilities affecting a HUGE range of Ryzen processors! • The flaws are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS scores of 8.5 and 8.3. • AMD says affected firmware TPM implementations could potentially expose TPM-protected data or allow falsified attestation keys, but exploitation requires local access with elevated privileges. • Affected chips include a massive range of Ryzen hardware, from Ryzen 3000 through Ryzen 9000, along with Ryzen AI, Threadripper and other AMD platforms. • AMD actually delivered many of the firmware mitigations back in May, before publicly disclosing the vulnerabilities. • Ryzen 9000 desktop systems are covered by newer ComboAM5PI 1.2.0.3k or 1.3.0.1b firmware. • Ryzen 3000 desktop systems received mitigation through ComboAM4PI 1.0.0.11, while newer AM4 systems use newer ComboAM4v2PI revisions. • AMD recommends checking your motherboard or system manufacturer for the latest BIOS update containing the required firmware. If you’re running a Ryzen system, especially AM4 or AM5, I’d check ASUS, MSI, GIGABYTE or your board maker and make sure you’re on a recent BIOS.
Post summary
AMD disclosed two high‑severity TPM flaws and released firmware patches; users must update BIOS to mitigate the risks, with no evidence yet of exploitation.











