AMD has already patched two TPM vulnerabilities that affected six generations of Ryzen
AMD has recognized that one of its most sensitive components, the trusted platform module or TPM, hid two vulnerabilities that had been silently being corrected for months. The company confirms that both bugs already have a patch available, although not all processors have received them yet.
The TPM is the piece of silicon (or firmware, in the case of the fTPM that AMD integrates into its own chips) responsible for saving encryption keys, managing secure boot and supporting functions such as BitLocker or the Windows 11 installation requirement itself. That something goes wrong there is no small detail: if an attacker manages to manipulate the TPM, they can suddenly compromise all the digital signatures and encryption that depend on it.
Two CVEs with scores of up to 8.5 out of 10
The origin of the problem is in a reading out of memory limits (known as OOB, out-of-bounds) present in the reference implementation of TPM 2.0. This flaw allowed malicious commands to be sent to the TPM itself and, in the worst case, completely bypass its operation. AMD has cataloged the discovery under two identifiers: CVE-2026-6726, with a CVSS score of 8.5, and CVE-2026-6727, somewhat less severe with a 8.3. Both figures are within the range that the industry considers critical.
What is striking is the extent of the TPM vulnerability. It’s not limited to a handful of recent models: it affects all AMD Ryzen desktop CPUs from the 3000 series to the 9000 series, virtually the entire range that has gone through the AM4 and AM5 sockets in recent years.
In June 2025, AMD had already fixed another bug related to the TPM using the AGESA 1.2.0.3e microcode, first distributed through an ASUS BIOS for the ROG Crosshair X870E Hero board, socket AM5. That patch resolved an out-of-bounds read vulnerability in fTPM, also discovered by the Trusted Computing Group, although limited to the 600 and 800 series chipsets.
The Ryzen AI 300 and AI Max 300, the last in the patch queue
Intel security researchers were the ones who detected the problem and They moved him to the Trusted Computing Group (TCG) and to its Vulnerability Response Team (VRT), the body that oversees the TPM standard across the industry. Since then, AMD has worked with motherboard manufacturers to distribute BIOS updates that close the security hole.
According to AMD, These updates have been distributed since Maywith some manufacturers shipping their first BIOSes as early as June and July. The August patch, the most recent, is the one that had yet to reach a specific group of processors: the Ryzen AI 300 and Ryzen AI 400 for desktops and laptops, along with the Ryzen AI Max 300 serieswhich will receive their Pluton security update this month.
Why a TPM vulnerability weighs so heavily on system security
The coordination between researchers from Intel, the TCG and AMD explains that the notice will arrive accompanied by a solution from the first momentsomething unusual when it comes to such a critical component. A compromised TPM not only puts disk encryption at risk: it also opens the door for an attacker to gain elevated system privileges and compromise security enclaves, bypassing the very piece of hardware that is supposed to protect them. AMD emphasizes that these types of failures are especially delicate in the hardware that supports the security of modern systems, where the TPM acts as the last barrier before an attack reaches the operating system itself.
For anyone who has a Ryzen from any of those generations, the recommendation is to check if the motherboard manufacturer has already published the corresponding BIOS and install it. On computers with Ryzen AI 300, AI 400 or AI Max 300, the patch is still on the way, so keep an eye on firmware updates that arrive during August.
