AMD has disclosed two high-severity vulnerabilities affecting the TPM 2.0 reference implementation code used across a wide range of its processors. Thankfully, both vulnerabilities have already been patched prior to the public announcement, meaning your system can be protected.
TPM 2.0 (firmware Trusted Platform Module), also called fTPM on AMD CPUs, is a technology built directly into modern AMD Ryzen, Threadripper, Epyc, and embedded processors. It’s used to store encryption keys and digital certificates safely, acting as a hardware-level shield against malware.
According to AMD, a potential out-of-bounds (OOB) read was present in the TPM 2.0 reference implementation code, which could be triggered from user-mode applications by sending malicious commands to a TPM 2.0 device whose firmware is based on an affected TCG (Trusted Computing Group) reference implementation.
The latter is the official source code provided to chip makers and software developers to use as a blueprint and simulator for hardware-based security. In other words, this vulnerability could send malicious commands to a TPM 2.0 device to bypass its security. If successfully exploited, the vulnerability could allow an attacker to read data stored in the TPM, or potentially impact TPM availability.
These vulnerabilities are referenced as CVE-2026-6726 and CVE-2026-6727, which received a CVSS severity score of 8.5 and 8.3, respectively, out of 10. The first can allow an attacker to obtain a credential for a falsified TPM key, such as an Attestation Key, DevID Key or TLS authentication key, plus the possibility to falsify other TPM 2.0 attestations with this key.
Meanwhile, the second could allow an attacker to decrypt ciphertexts that can be used to falsify TPM 2.0 Attestation Keys. Thankfully, both vulnerabilities require local privileged access, meaning that they’re more of a concern for professional sectors, and less for home users.
These vulnerabilities have been discovered by Intel security researchers and affect all kinds of AMD processors, from Athlon 3000 mobile CPUs to the top-end Ryzen 9 9950X3D2, along with Epyc 4005 and Ryzen Embedded 5000-series chips.
The good news is that AMD has been working with motherboard vendors to ship updates and secure affected platforms since May 2026, meaning that your system, be it DIY or OEM, should already have a patch available. If you have updated your motherboard BIOS recently, you may well already be protected.

