AMD patches TPM flaws in Ryzen systems
AMD confirmed vulnerabilities in the trusted platform module tied to a potential out-of-bounds (OOB) read in the TPM 2.0 reference implementation. The flaw could allow malicious commands to be sent to TPM 2.0 and bypass its protections, potentially compromising digital signing and encryption if an attacker gained access and disabled the module.
The issues are tracked as CVE-2026-6726 with a CVSS score of 8.5 and CVE-2026-6727 with a CVSS score of 8.3, and affected every AMD Ryzen CPU from the 3000 to 9000 series of desktop processors. Intel security researchers reported the problem to the Trusted Computing Group and its Vulnerability Response Team. AMD has coordinated with motherboard vendors, which began distributing patches in May, with additional updates in June and July. Remaining updates for AMD Ryzen AI 300 series, Ryzen AI 400 desktop and notebook series, and Ryzen AI Max 300 series processors are scheduled to receive Pluton secure processor updates this month.