Trusted Platform Module (TPM) Reference Code Errata

Summary

The Trusted Computing Group (TCG) Vulnerability Response Team (VRT) has reported a potential out of bounds (OOB) read vulnerability in the Trusted Platform Module (TPM) 2.0 reference implementation code. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0 whose firmware is based on an affected TCG reference implementation.  If successfully exploited, the vulnerability could allow an attacker to read data stored in the TPM or potentially impact TPM availability.

AMD has analyzed the Trusted Computing Group’s report and believes Firmware TPMs on AMD platforms are impacted by this vulnerability.

CVE Details

Refer to Glossary for explanation of terms

CVE CVE Description CVSS Score
CVE-2026-6726 (non-AMD) An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA  for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. 8.5 High CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVE-2026-6727 (non-AMD) A timing side-channel vulnerability in RSA OAEP decryption was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to decrypt ciphertexts (import blobs, credential blobs, and session salts) encrypted to the RSA Endorsement Key or falsify TPM 2.0 Attestation Keys. 8.3 High CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products and Mitigation

AMD recommends updating to the Platform Initialization (PI) firmware version indicated below (note the PI firmware versions were released by AMD to the Original Equipment Manufacturers (OEM) on the dates listed below). Please contact your OEM for the BIOS update specific to your product(s).

AMD EPYC™ Series Processors 

Product

CVE ID

Platform Initialization (PI) Mitigation

PI Release Date

AMD EPYC™ 4004 Series Processors

CVE-2026-6726 (non-AMD)

ComboAM5PI 1.2.0.3k

2026-05-31

CVE-2026-6727 (non-AMD)

ComboAM5PI 1.2.0.3k

2026-05-31

AMD EPYC™ 4005 Series Processors

CVE-2026-6726 (non-AMD)

ComboAM5PI 1.2.0.3k

2026-05-31

CVE-2026-6727 (non-AMD)

ComboAM5PI 1.2.0.3k

2026-05-31

AMD EPYC™ Embedded Series Processors
Product CVE ID Mitigation Mitigation Release Date
AMD EPYC™ Embedded 2005 Series Processors

CVE-2026-6727 (non-AMD)

EmbeddedFireRangeFL1_1.0.0.4A 2026-06-30
AMD EPYC™ Embedded 4005 Series Processors CVE-2026-6726 (non-AMD) EmbeddedAM5PI_1.0.0.8 2026-07-01
CVE-2026-6727 (non-AMD) EmbeddedAM5PI_1.0.0.8 2026-07-01
AMD Ryzen™ Embedded Series Processors
Product CVE ID Mitigation Mitigation Release Date
AMD Ryzen™ Embedded 5000 Series Processors CVE-2026-6726
(non-AMD)
EmbAM4PI_1.0.0.A 2026-07-31
CVE-2026-6727
(non-AMD)
EmbAM4PI_1.0.0.A 2026-07-01
AMD Ryzen™ Embedded 7000 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedAM5PI_1.0.0.8 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedAM5PI_1.0.0.8 2026-07-01
AMD Ryzen™ Embedded 8000 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedPhoenixPI-FP7r2_1.0.0.5 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedPhoenixPI-FP7r2_1.0.0.5 2026-07-01
AMD Ryzen™ Embedded 9000 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedAM5PI_1.0.0.8 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedAM5PI_1.0.0.8 2026-07-01
AMD Ryzen™ Embedded P100 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedP100 PI 1000 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedP100 PI 1000 2026-07-01
AMD Ryzen™ Embedded R1000 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedPI-FP5 1215 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedPI-FP5 1215 2026-07-01
AMD Ryzen™ Embedded R2000 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedR2KPI-FP5_1.0.0.9 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedR2KPI-FP5_1.0.0.9 2026-07-01
AMD Ryzen™ Embedded V1000 Series Processors (formerly codenamed "Raven Ridge") CVE-2026-6726
(non-AMD)
EmbeddedPI-FP5 1215 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedPI-FP5 1215 2026-07-01
AMD Ryzen™ Embedded V2000 Series Processors CVE-2026-6726
(non-AMD)
EmbeddedPI-FP6_100E 2026-07-01
CVE-2026-6727
(non-AMD)
EmbeddedPI-FP6_100E 2026-07-01
AMD Ryzen™ Embedded V3000 Series Processors CVE-2026-6726
(non-AMD)
Embedded-PI_FP7r2 1013 2026-07-01
CVE-2026-6727
(non-AMD)
Embedded-PI_FP7r2 1013 2026-07-01
AMD Athlon™ Series Processors
Product CVE ID Mitigation Mitigation Release Date
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
PicassoPI-FP5_1.0.1.2f 2026-05-15
CVE-2026-6727
(non-AMD)
PicassoPI-FP5_1.0.1.2f 2026-05-15
AMD Ryzen™ Series Processors
Product CVE ID Mitigation Mitigation Release Date
AMD Ryzen™ 3000 Series Desktop Processors CVE-2026-6726
(non-AMD)
ComboAM4PI_1.0.0.11 2026-05-18
ComboAM4 1.0.0.11 2026-05-18
CVE-2026-6727
(non-AMD)
ComboAM4PI_1.0.0.11 2026-05-18
ComboAM4 1.0.0.11 2026-05-18
AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
PicassoPI-FP5_1.0.1.2f 2026-05-15
CVE-2026-6727
(non-AMD)
PicassoPI-FP5_1.0.1.2f 2026-05-15
AMD Ryzen™ 4000 Series Desktop Processors CVE-2026-6727
(non-AMD)
ComboAM4v2PI_1.2.0.12 2026-05-27
CVE-2026-6727
(non-AMD)
ComboAM4v2PI_1.2.0.12 2026-05-27
AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
RenoirPI-FP6_1.0.0.Ee 2026-05-18
CVE-2026-6727
(non-AMD)
RenoirPI-FP6_1.0.0.Ee 2026-05-18
AMD Ryzen™ 5000 Series Desktop Processors CVE-2026-6726
(non-AMD)
ComboAM4v2PI_1.2.0.12 2026-05-27
CVE-2026-6727
(non-AMD)
ComboAM4v2PI_1.2.0.12 2026-05-27
AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
ComboAM4v2PI_1.2.0.12 2026-05-27
CVE-2026-6727
(non-AMD)
ComboAM4v2PI_1.2.0.12 2026-05-27
AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
CezannePI-FP6_1.0.1.1e 2026-05-15
CVE-2026-6727
(non-AMD)
CezannePI-FP6_1.0.1.1e 2026-05-15
AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
RembrandtPI-FP7_1.0.0.Bh 2026-05-12
CVE-2026-6727
(non-AMD)
RembrandtPI-FP7_1.0.0.Bh 2026-05-12
AMD Ryzen™ 7000 Series Desktop Processors CVE-2026-6726
(non-AMD)
ComboAM5PI 1.2.0.3k 2026-05-31
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.2.0.3k 2026-05-31
CVE-2026-6726
(non-AMD)
ComboAM5PI 1.3.0.1b 2026-05-21
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.3.0.1b 2026-05-21
CVE-2026-6726
(non-AMD)
ComboAM5PI 1.1.0.3h 2026-05-13
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.1.0.3h 2026-05-13
CVE-2026-6726
(non-AMD)
ComboAM5PI 1.0.0.F 2026-05-08
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.0.0.F 2026-05-08
AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
MendocinoPI-FT6_1.0.0.7i 2026-05-12
CVE-2026-6727
(non-AMD)
MendocinoPI-FT6_1.0.0.7i 2026-05-12
AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
CezannePI-FP6_1.0.1.1e 2026-06-15
CVE-2026-6727
(non-AMD)
CezannePI-FP6_1.0.1.1e 2026-06-15
AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
RembrandtPI-FP7_1.0.0.Bh 2026-05-12
CVE-2026-6727
(non-AMD)
RembrandtPI-FP7_1.0.0.Bh 2026-05-12
AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
PhoenixPI-FP8-FP7_1.2.0.h 2026-06-01
CVE-2026-6727
(non-AMD)
PhoenixPI-FP8-FP7_1.2.0.h 2026-06-01
AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
DragonRangeFL1PI 1.0.0.3m 2026-05-13
CVE-2026-6727
(non-AMD)
DragonRangeFL1PI 1.0.0.3m 2026-05-13
AMD Ryzen™ 8000 Series Desktop Processors CVE-2026-6726
(non-AMD)
ComboAM5PI 1.1.0.3h 2026-05-31
ComboAM5PI 1.2.0.3k 2026-05-31
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.1.0.3h 2026-05-31
ComboAM5PI 1.2.0.3k 2026-05-31
CVE-2026-6726
(non-AMD)
ComboAM5PI 1.3.0.1b 2026-05-21
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.3.0.1b 2026-05-21
AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726
(non-AMD)
PhoenixPI-FP8-FP7_1.2.0.h 2026-06-01
CVE-2026-6727
(non-AMD)
PhoenixPI-FP8-FP7_1.2.0.h 2026-06-01
AMD Ryzen™ 9000 Series Desktop Processors CVE-2026-6726
(non-AMD)
ComboAM5PI 1.2.0.3k 2026-05-31
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.2.0.3k 2026-05-31
CVE-2026-6726
(non-AMD)
ComboAM5PI 1.3.0.1b 2026-05-21
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.3.0.1b 2026-05-21
AMD Ryzen™ 9000HX Series Processors CVE-2026-6726
(non-AMD)
FireRangeFL1PI 1.0.0.0g 2026-05-12
CVE-2026-6727
(non-AMD)
FireRangeFL1PI 1.0.0.0g 2026-05-12
AMD Ryzen™ AI 300 Series Processors CVE-2026-6726
(non-AMD)
StrixKrackanPI-FP8_1.1.0.0g (5/26/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
StrixKrackanPI-FP8_1.1.0.2f (6/8/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
CVE-2026-6727
(non-AMD)
StrixKrackanPI-FP8_1.1.0.0g (5/26/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
StrixKrackanPI-FP8_1.1.0.2f (6/8/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
AMD Ryzen™ AI 400 Series Desktop Processors CVE-2026-6726
(non-AMD)
ComboAM5PI 1.3.0.1b (5/21/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
CVE-2026-6727
(non-AMD)
ComboAM5PI 1.3.0.1b (5/21/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
AMD Ryzen™ AI 400 Series Processors CVE-2026-6726
(non-AMD)
GorgonPI-FP8_1.0.0.2d (6/16/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
CVE-2026-6727
(non-AMD)
GorgonPI-FP8_1.0.0.2d (6/16/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
AMD Ryzen™ AI Max 300 Series Processors CVE-2026-6726
(non-AMD)
StrixHalo PI-FP11_1.0.0.2c (6/8/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
CVE-2026-6727
(non-AMD)
StrixHalo PI-FP11_1.0.0.2c (6/8/26 fTPM ONLY) Target release planned for Aug’26 (Pluton)
AMD Ryzen™ Threadripper™ 7000 Processors CVE-2026-6726
(non-AMD)
StormPeakPI-SP6_1.1.0.0l 2026-05-11
CVE-2026-6727
(non-AMD)
StormPeakPI-SP6_1.1.0.0l 2026-05-11
AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors CVE-2026-6726
(non-AMD)
ChagallWSPI-sWRX8 1.0.0.f 2026-05-17
CastlePeakWSPI-sWRX8 1.0.0.J 2026-05-17
CVE-2026-6727
(non-AMD)
ChagallWSPI-sWRX8 1.0.0.f 2026-05-17
CastlePeakWSPI-sWRX8 1.0.0.J 2026-05-17
AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors CVE-2026-6726
(non-AMD)
ChagallWSPI-sWRX8 1.0.0.f 2026-05-17
CVE-2026-6727
(non-AMD)
ChagallWSPI-sWRX8 1.0.0.f 2026-05-17
AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors CVE-2026-6726
(non-AMD)
StormPeakPI-SP6_1.0.0.1n 2026-05-11
CVE-2026-6727
(non-AMD)
StormPeakPI-SP6_1.0.0.1n 2026-05-11
AMD Ryzen™ Z1 Series Processors CVE-2026-6726
(non-AMD)
PhoenixPI-FP8-FP7_1.2.0.0h 2026-06-01
CVE-2026-6727
(non-AMD)
PhoenixPI-FP8-FP7_1.2.0.0h 2026-06-01
AMD Ryzen™ Z2 Series Processors CVE-2026-6726
(non-AMD)
StrixKrackanPI-FP8_1.1.0.0g 2026-05-26
CVE-2026-6727
(non-AMD)
StrixKrackanPI-FP8_1.1.0.0g 2026-05-26

Acknowledgement 

Reported to the Trusted Computing Group (TCG) by Intel security researchers

Revisions

Revision Date Description
2026-08-11 Initial publication  

DISCLAIMER

The information contained herein is for informational purposes only and is subject to change without notice. While every precaution has been taken in the preparation of this document, it may contain technical inaccuracies, omissions and typographical errors, and AMD is under no obligation to update or otherwise correct this information. Advanced Micro Devices, Inc. makes no representations or warranties with respect to the accuracy or completeness of the contents of this document, and assumes no liability of any kind, including the implied warranties of noninfringement, merchantability or fitness for particular purposes, with respect to the operation or use of AMD hardware, software or other products described herein. Any computer system has risks of security vulnerabilities that cannot be completely prevented or mitigated. No license, including implied or arising by estoppel, to any intellectual property rights is granted by this document. Terms and limitations applicable to the purchase or use of AMD’s products are as set forth in a signed agreement between the parties or in AMD's Standard Terms and Conditions of Sale.

AMD, the AMD Arrow logo, Athlon, EPYC, Ryzen, Radeon, Threadripper and combinations thereof are trademarks of Advanced Micro Devices, Inc. CVE and the CVE logo are registered trademarks of The MITRE Corporation. Other product names used in this publication are for identification purposes only and may be trademarks of their respective companies.

Third party content may be licensed to you directly by the third party that owns the content and is not licensed to you by AMD. ALL LINKED THIRD-PARTY CONTENT IS PROVIDED ‘AS IS’ WITHOUT A WARRANTY OF ANY KIND. USE OF SUCH THIRD-PARTY CONTENT IS DONE AT YOUR SOLE DISCRETION AND UNDER NO CIRCUMSTANCES WILL AMD BE LIABLE TO YOU FOR ANY THIRD PARTY CONTENT. YOU ASSUME ALL RISK AND ARE SOLELY RESPONSIBILITY FOR ANY DAMAGES THAT MAY ARISE FROM YOUR USE OF THIRD-PARTY CONTENT.

© 2026 Advanced Micro Devices, Inc. All rights reserved.