CVE-2026-6727Patch

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 24 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 6 signals
  • General: 8 classified signals
  • Disclosure: 5 classified signals
  • Peaked 7d ago at 8 mentions (2026-08-12); latest day: 2
  • 24 total mentions across 9 days

Deep dive

Activity timeline24 mentions / 9d
02468Mentions · 2026-08-11: 2Mentions · 2026-08-12: 8Mentions · 2026-08-13: 3Mentions · 2026-08-14: 3Mentions · 2026-08-15: 2Mentions · 2026-08-16: 1Mentions · 2026-08-17: 2Mentions · 2026-08-27: 1Mentions · 2026-09-20: 2Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 4Patch / Workaround · 2026-08-13: 3Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-12: 3Technical Details · 2026-08-13: 308-1108-1208-1308-1408-1508-1608-1708-2709-20
Signal classification3 categories
Patch
940.9%
General
836.4%
Disclosure
522.7%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-08-112
Disclosure1General1
2026-08-128
Disclosure3General1Patch4
2026-08-133
Patch3
2026-08-143
General2Patch1
2026-08-152
General2
2026-08-161
General1
2026-08-172
Disclosure1General1
2026-08-271
Patch1
Full discourse20 posts
  • Chris Mizo@MizoChris
    Patch

    AMD has confirmed two high-severity TPM vulnerabilities affecting a HUGE range of Ryzen processors! • The flaws are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS scores of 8.5 and 8.3. • AMD says affected firmware TPM implementations could potentially expose TPM-protected data or allow falsified attestation keys, but exploitation requires local access with elevated privileges. • Affected chips include a massive range of Ryzen hardware, from Ryzen 3000 through Ryzen 9000, along with Ryzen AI, Threadripper and other AMD platforms. • AMD actually delivered many of the firmware mitigations back in May, before publicly disclosing the vulnerabilities. • Ryzen 9000 desktop systems are covered by newer ComboAM5PI 1.2.0.3k or 1.3.0.1b firmware. • Ryzen 3000 desktop systems received mitigation through ComboAM4PI 1.0.0.11, while newer AM4 systems use newer ComboAM4v2PI revisions. • AMD recommends checking your motherboard or system manufacturer for the latest BIOS update containing the required firmware. If you’re running a Ryzen system, especially AM4 or AM5, I’d check ASUS, MSI, GIGABYTE or your board maker and make sure you’re on a recent BIOS.

    Post summary

    AMD disclosed two high‑severity TPM vulnerabilities affecting Ryzen processors and has released firmware mitigations; users are advised to update their BIOS to resolve the issue.

    172632389718.2K
    3.0K followersView on X
  • ShaiHasarfaty@hasarfaty
    Disclosure

    It's been over a year since @yanaimoyal and I discovered CVE-2026-6727. This issue affected more than one vendor, but this is one of the first to publicly share the CVE fix also need to thank David Hai Gootvilig and Liran Perez for aiding with analysis https://trustedcomputinggroup.org/wp-content/uploads/VRT0011-Advisory_Final.pdf

    Post summary

    The tweet announces the discovery of CVE‑2026‑6727 and links to an advisory that publicly shares the fix, but provides no PoC, exploit, or detailed technical information.

    02041215
    218 followersView on X
  • JVN 脆弱性レポート@jvnjp
    Disclosure

    [2026/08/12 10:30 公表] TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727) https://jvn.jp/vu/JVNVU96623328/index.html

    Post summary

    The JVN advisory announces two new CVEs (CVE-2026-6726 and CVE-2026-6727) affecting the TCG TPM2.0 reference implementation, with no additional details on PoC, exploitation, or patches provided.

    031202.3K
    25.5K followersView on X
  • inconnu inconnu@inconnu34283172
    Disclosure

    @Pirat_Nation The vulnerabilities are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS 4.0 scores of 8.5 and 8.3 respectively. AMD says its Firmware TPM implementations are affected. https://videocardz.com/newz/amd-confirms-ryzen-tpm-vulnerabilities-asus-msi-and-gigabyte-already-have-fixes

    Post summary

    AMD confirmed two Ryzen Firmware TPM vulnerabilities (CVE-2026-6726/6727) with CVSS scores of 8.5 and 8.3, impacting Firmware TPM implementations; the release notes suggest fixes are likely in place.

    00030164
    83 followersView on X
  • 乖離(*´∀`)🍑😊🐻😾☔🎵🍢🌸💯🗽🇯🇵🗻🏝️🌲🏡🆓🎮🚗🚴💨@kai_ri_0001

    https://kb.cert.org/vuls/id/431093 CVE-2026-6726 – 改ざんされたTPMキーによる情報漏洩。 CVE-2026-6727 – RSA OAEP復号化におけるタイミングサイドチャネルの脆弱性。

    1000076
    16.5K followersView on X
  • 乖離(*´∀`)🍑😊🐻😾☔🎵🍢🌸💯🗽🇯🇵🗻🏝️🌲🏡🆓🎮🚗🚴💨@kai_ri_0001

    X570 AORUS MASTER (Rev. 1.1/1.2) Checksum: 1E34 Update AM4 AGESA ComboV2 1.2.0.12 Fix AMD TPM Reference Code Errata (CVE-2026-6726, CVE-2026-6727) F40d11.02 MBSep 17, 2026 https://www.gigabyte.com/jp/Motherboard/X570-AORUS-MASTER-rev-11-12/support#Support-Bios

    10000252
    16.5K followersView on X
  • しーにゃ♪@公式@Syynya
    Disclosure

    JVNVU#96623328 TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727) https://jvn.jp/vu/JVNVU96623328/index.html ぉ。

    Post summary

    The post announces multiple vulnerabilities (CVE-2026-6726 and CVE-2026-6727) in the TCG TPM 2.0 reference implementation, but provides no PoC, exploit, active exploitation, patch, or technical details.

    1000047
    910 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The tweet merely raises a question about initial response steps for TCG TPM2.0 vulnerabilities (CVE‑2026‑6726/6727) without providing further technical or mitigation details.

    0001069
    842 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The post merely poses a question about the initial response steps if the referenced CVEs are detected, offering no technical, exploit, or patch details.

    0001048
    843 followersView on X
  • Human Firewall@HumanFirewallHQ
    Patch

    Two TPM 2.0 reference-implementation bugs also closed: CVE-2026-6726 (spoofing) and CVE-2026-6727 (timing side-channel). The wrinkle: Windows Update alone can't fully fix them — your OEM's firmware has to. That part is a slower calendar than a KB article.

    Post summary

    Two TPM 2.0 reference‑implementation bugs (CVE‑2026‑6726 spoofing and CVE‑2026‑6727 timing side‑channel) have been closed; Windows Update alone does not fully remediate them, so OEM firmware updates are needed.

    1000048
    2 followersView on X
  • Framebuffer D3lta@framebuffer_br
    Patch

    CVE-2026-6727 com pontuações CVSS de 8.5 e 8.3 respectivamente, foi descoberta por pesquisadores da Intel e corrigida pelas fabricantes de placas-mãe a partir de maio deste ano, sendo que as CPUs Ryzen AI mais recentes receberão o patch em agosto. ➡️

    Post summary

    An Intel‑discovered vulnerability CVE‑2026‑6727 with CVSS scores of 8.5/8.3 is reported, and motherboard manufacturers have released a patch effective from May, with Ryzen AI CPUs getting the update in August.

    1000063
    483 followersView on X
  • inconnu inconnu@inconnu34283172
    Patch

    @pin123345 @Pirat_Nation The vulnerabilities are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS 4.0 scores of 8.5 and 8.3 respectively. AMD says its Firmware TPM implementations are affected. https://videocardz.com/newz/amd-confirms-ryzen-tpm-vulnerabilities-asus-msi-and-gigabyte-already-have-fixes

    Post summary

    New TPM firmware vulnerabilities (CVE-2026-6726/6727) were disclosed with high CVSS scores, and motherboard makers have already issued patches.

    1000061
    83 followersView on X
  • くろがねッと☆@kuroganet39
    Patch

    ASUS PRIME A520M-K PRIME A520M-E バージョン 3644 15.97 MB 2026/08/27 "1. Update AGESA version to ComboV2 PI 1.2.0.12. 2. Mitigate fTPM vulnerabilities (CVE-2026-6726, CVE-2026-6727)."

    Post summary

    The release note announces a firmware update for ASUS PRIME boards that addresses fTPM vulnerabilities CVE-2026-6726 and CVE-2026-6727.

    0000091
    1.2K followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post provides a high‑level analysis of CVE-2026‑6726 and CVE-2026‑6727 but does not supply technical details, PoC code, patches, or evidence of exploitation.

    0000059
    842 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post references two CVEs affecting the TCG TPM 2.0 reference implementation, giving only a high‑level commentary without detailed technical, exploit, patch, or operational information.

    0000072
    843 followersView on X
  • Stefan Klatt@TheUnicornXXL
    Patch

    AMD schließt TPM-Lücken bei zahlreichen Ryzen-CPUs https://www.connect.de/news/amd-ryzen-tpm-sicherheitsluecke-cve-2026-6726-cve-2026-6727-mainboard-firmware-updates-3213117.html

    Post summary

    The text reports that AMD is applying firmware updates to close identified TPM vulnerabilities in Ryzen CPUs, but provides no evidence of active exploitation or detailed technical information.

    0000066
    1.4K followersView on X
  • ゆぅさん@YY20424277
    General

    「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The text lists two CVE identifiers related to TCG TPM2.0 reference implementation but provides no further technical or operational details.

    0000054
    843 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The post poses a general question about initial incident response steps for CVE‑2026‑6726 and CVE‑2026‑6727, without providing specific technical details, exploits, or mitigation information.

    0000065
    843 followersView on X
  • Ahmet Can@0xbo79
    Patch

    Güven zincirinin kökü sızdırıyor. TCG TPM 2.0 referans kodunda iki açık: CVE-2026-6726 - CVE-2026-6727 CVSS ~8.5 / 8.3. AMD + Intel fTPM’lerde (firmware TPM). Ne demek: TPM, BitLocker / attestation / “bu cihaz güvenilir mi?” sorularının dayandığı küçük güvenlik çekirdeği. Biri timing ile sır sızdırıyor (RSA-OAEP). Öteki geçersiz kılınmış anahtarı doğru temizlemeyebiliyor - sahte attestation kapısı. İyi kısım: yerel + yüksek yetki lazım. Ev kullanıcısı için uzak “tek tık hack” değil. Kötü kısım: kurumsal notebook ele geçince “güvenli cihaz” maskesiyle ağın içine yürüme riski. AMD Mayıs’ta OEM’lere AGESA/firmware vermiş; ASUS / MSI / Gigabyte BIOS’ları çıkmaya başlamış. Intel tarafı da bulletin + BIOS hattı. Patch’i BIOS’ta bırakmak “sonra bakarız” mı oluyor, yoksa fleet’te zorunlu mı? #TPM #AMD #Cybersecurity

    Post summary

    Two TPM 2.0 reference‑code CVEs (CVE‑2026‑6726/CVE‑2026‑6727) score ~8.5 / 8.3 CVSS and allow secret leakage via timing and forged attestation; local high‑privilege is required, but corporate devices could be exploited, with patches available through BIOS firmware updates.

    0000073
    81 followersView on X
  • inconnu inconnu@inconnu34283172
    Patch

    @PAX_PC @PAX_PC failles critiques ou la seule façon de corriger est de flasher le bios des cartes meres Les vulnérabilités sont suivies sous les noms de CVE-2026-6726 et CVE-2026-6727, https://videocardz.com/newz/amd-confirms-ryzen-tpm-vulnerabilities-asus-msi-and-gigabyte-already-have-fixes

    Post summary

    The tweet highlights two critical AMD Ryzen TPM vulnerabilities (CVE‑2026‑6726/6727) and notes that the only remedy is to flash the motherboard BIOS, with vendors already releasing fixes.

    0000053
    83 followersView on X

Explore more