AMD patches two high-severity TPM vulnerabilities in Epyc, Ryzen with CVSS 8.5 and 8.3
AMD has disclosed two high-severity vulnerabilities in its TPM reference implementation, with CVSS scores of 8.5 and 8.3, affecting Epyc, Ryzen, Threadripper, and embedded processors. The flaws, including CVE-2026-6727, require local privileged access and are not remotely exploitable. Firmware fixes have been available since May 2026 for most processors, with Ryzen embedded updates completed in July. The vulnerabilities were identified by TCG researchers.
AMD has released security advisory AMD-SB-7064, disclosing two high-severity vulnerabilities in the TPM (Trusted Platform Module) reference implementation used in its computer platforms. Researchers collaborating with the Trusted Computing Group (TCG) previously identified potential security flaws in AMD's TPM code, triggering updates to related motherboards and firmware. The fix code was released several months ago, but AMD only recently made the full details of the advisory public.
CVE-2026-6727 is described as a timing side-channel vulnerability affecting workloads that use the RSA cryptosystem for decryption. An attacker could exploit it to decrypt encrypted data or forge TPM 2.0 attestation keys. Both vulnerabilities require local access with privileged user permissions and do not pose a direct remote attack risk to systems exposed only to the internet.
The two vulnerabilities have CVSS severity scores of 8.5 and 8.3, respectively, and affect a wide range of processors. AMD's list of affected products includes Epyc 4004 and 4005 series server processors, multiple embedded processors, Ryzen desktop processors from the 3000 to 9000 series, and Threadripper workstation processors. Fixed firmware for most processors has been available since May 2026, with updated firmware for Ryzen embedded CPUs completed in July.
TPM is a security hardware specification developed by the Trusted Computing Group in 2003, upgraded to version 2.0 in 2014, and subsequently became a mandatory hardware requirement for Windows 11. The two vulnerabilities disclosed by AMD highlight the need for continued security maintenance in modern PC environments where TPM is widely deployed.