AMD discloses critical TPM flaws affecting a wide range of Ryzen processors

AMD has revealed two serious security flaws in its Trusted Platform Module 2.0 implementations across numerous Ryzen processors, with patches already issued ahead of public disclosure, raising concerns over system security and firmware updates.

AMD has disclosed two serious flaws in the Trusted Platform Module 2.0 implementations used across a broad range of Ryzen processors, saying patches were delivered to board and system makers weeks before the public bulletin. The company’s new security notice, AMD-SB-7064, identifies the issues as CVE-2026-6726 and CVE-2026-6727, with CVSS 4.0 scores of 8.5 and 8.3. According to AMD, both affect TPM-related security functions rather than the main CPU cores.

The first flaw could let a local attacker with elevated privileges extract credentials for a forged TPM key and tamper with TPM attestation, which is the process used to prove a system has not been altered. The second is described as a timing side channel in RSA OAEP, a public-key encryption scheme, that could expose TPM-encrypted data or allow an attacker to counterfeit attestation keys. AMD said the bugs were reported through the Trusted Computing Group by security researchers at Intel.

The affected product list is wide. It includes Ryzen 3000 through Ryzen 9000 desktop chips, Ryzen AI 300 and 400 parts, Ryzen AI Max 300, Threadripper, Ryzen Z1 and Z2 processors and several Ryzen Embedded families. AMD said most desktop fixes were issued in May, including ComboAM4PI 1.0.0.11 for Ryzen 3000 on May 18, ComboAM4v2PI 1.2.0.12 for Ryzen 4000 and Ryzen 5000 on May 27, and ComboAM5PI 1.3.0.1b and 1.2.0.3k for Ryzen 7000, Ryzen 8000 and Ryzen 9000 systems.

Motherboard vendors have since been rolling out BIOS updates based on those AGESA releases. VideoCardz reported that Asus began shipping updates in early June, followed by Gigabyte in June, MSI in early July and ASRock in the second half of July. The disclosure comes as AMD has also faced criticism over recent firmware changes to consumer Ryzen security features, but the company says the TPM issue has already been addressed through its partner update channel.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.