AMD disclosed CVE 2026 6726 (CVSS 8.5, out of bounds read) and CVE 2026 6727 (CVSS 8.3, timing side channel) on August 11–13, 2026, affecting Ryzen 3000 through 9000 series, Threadripper, EPYC 4004/4005, and embedded... The two TPM 2.0 flaws (CVE 2026 6726 and CVE 2026 6727) require local privileged access and canno...
Research answer

Create a landscape editorial hero image for this Studio Global article: What are the key details of the two high-severity TPM vulnerabilities (CVE-2026-6726 and CVE-2026-6727) AMD disclosed in August 2026 that af. Article summary: On August 11–13, 2026, AMD disclosed two high-severity TPM 2.0 vulnerabilities as part of its AMD-SB-7064 security bulletin, affecting Ryzen 3000 through 9000 series, Threadripper, EPYC, and embedded processors. Both fla. Topic tags: general, government, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake n
On August 11–13, 2026, AMD disclosed two high-severity TPM 2.0 vulnerabilities as part of its AMD-SB-7064 security bulletin, affecting Ryzen 3000 through 9000 series, Threadripper, EPYC, and embedded processors. Both flaws originate in the TCG TPM 2.0 reference code and were reported by Intel researchers. Firmware fixes (platform initialization updates) have been available since May–June 2026, and major motherboard vendors (ASUS, MSI, Gigabyte, ASRock) have already released patched BIOS versions .
The vulnerabilities span an exceptionally broad range of AMD processors:
Both CVEs were republished by MITRE and appeared in Microsoft's August 2026 Patch Tuesday (August 11, 2026) under the "Windows TPM" tag, rated Important severity . However, Microsoft did not release a Windows-side security update or KB article for either CVE — only the underlying TPM firmware (BIOS/UEFI) update from the hardware vendor remediates the flaw
. The August 2026 Patch Tuesday batch overall addressed 421 CVEs, with these TPM vulnerabilities being high-profile items due to the broad AMD product scope and the origin of the disclosure (Intel researchers reporting TPM bugs affecting AMD systems)
.
Both vulnerabilities require local privileged access, meaning the risk for home users is low, but enterprise customers should prioritize BIOS updates on shared or multi-user systems. To mitigate the risk:
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
AMD disclosed CVE 2026 6726 (CVSS 8.5, out of bounds read) and CVE 2026 6727 (CVSS 8.3, timing side channel) on August 11–13, 2026, affecting Ryzen 3000 through 9000 series, Threadripper, EPYC 4004/4005, and embedded...
AMD disclosed CVE 2026 6726 (CVSS 8.5, out of bounds read) and CVE 2026 6727 (CVSS 8.3, timing side channel) on August 11–13, 2026, affecting Ryzen 3000 through 9000 series, Threadripper, EPYC 4004/4005, and embedded... The two TPM 2.0 flaws (CVE 2026 6726 and CVE 2026 6727) require local privileged access and cannot be exploited remotely, making them a moderate risk for most users but a serious concern for enterprise environments wi...