AMD disclosed two high-severity security flaws in its Ryzen processors that could allow attackers to steal credentials or forge hardware trust signatures. These vulnerabilities target the Trusted Platform Module (TPM) functionality built into many modern CPUs, which means users relying on device encryption or secure boot features face a tangible risk. We need to track these fixes because they impact system integrity across a wide range of desktop and laptop hardware.
Motherboard vendors release patches for credential theft and attestation forgery risks
The flaws, identified as CVE-2026-6726 and CVE-2026-6727, affect a broad spectrum of AMD silicon including Ryzen 3000 through 9000 series, Threadripper, Ryzen AI, and embedded families. CVE-2026-6726 carries a CVSS score of 8.5 and allows a local attacker with elevated privileges to obtain credentials for a falsified TPM key. The second flaw, CVE-2026-6727, scores 8.3 and exploits an RSA OAEP timing side-channel to expose encrypted TPM data or create falsified Attestation Keys.
- CVE-2026-6726: CVSS 8.5; Local attacker with elevated privileges can obtain credentials for a falsified TPM key and falsify TPM attestations
- CVE-2026-6727: CVSS 8.3; RSA OAEP timing side-channel that can expose encrypted TPM data or allow falsified Attestation Keys
- Affected Platforms: Ryzen 3000 through Ryzen 9000, Ryzen AI 300/400, Ryzen AI Max 300, Threadripper, Ryzen Z1/Z2, and several Ryzen Embedded families
- Ryzen 3000 Fix: ComboAM4PI 1.0.0.11 released May 18
- Ryzen 4000/5000 Fix: ComboAM4v2PI 1.2.0.12 released to OEMs May 27
AMD addressed these issues by supplying microcode updates to motherboard manufacturers in May 2024, prior to the public release of bulletin AMD-SB-7064. The company provided specific firmware revisions for different processor generations to ensure compatibility. Ryzen 3000 systems received ComboAM4PI version 1.0.0.11 on May 18, while Ryzen 4000 and 5000 models got ComboAM4v2PI 1.2.0.12 on May 27.
For newer Ryzen 7000, 8000, and 9000 platforms, AMD listed mitigated ComboAM5PI revisions 1.3.0.1b and 1.2.0.3k, released on May 21 and May 31 respectively. Major motherboard vendors including ASUS, MSI, GIGABYTE, and ASRock had already integrated these fixes into BIOS updates by June and July 2024. We touched on ASUS Motherboard Prices Rise for Intel in our earlier Amd coverage, but the current focus remains on securing these specific processor vulnerabilities.
Users should update their system BIOS immediately to apply these microcode patches and close the security gaps. The fixes are available through standard motherboard vendor update channels for all affected Ryzen generations.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.