AMD patches TPM flaws that could enable credential forgery and data exposure
Millions of AMD Ryzen-powered devices were affected.

Image by Dado Ruvic | Reuters
- AMD patched two high-severity TPM flaws affecting several Ryzen CPUs used in Windows 11 devices.
- Attackers with elevated privileges could exploit the flaws to read TPM-stored data, including private keys.
- Successful attacks could disable TPM protections, disrupting security features such as BitLocker and Windows Hello.
- AMD urges users to install updated Platform Initialization firmware through BIOS updates from motherboard manufacturers.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Security researchers have identified flaws in a Windows 11 Trusted Platform Module (TPM), potentially affecting security features that rely on it.
The Trusted Platform Module, or TPM, is a separate chip that performs cryptographic operations within a computer and stores sensitive data. It’s used to securely store encryption keys, passwords, certificates, and other data.
In addition, the TPM performs cryptographic operations such as generating random numbers, encrypting and decrypting data, and verifying digital signatures.
Windows 11 uses TPM 2.0 for many features, including Windows Hello and BitLocker. As a result, TPM 2.0 is one of the system requirements for Windows 11.
“TPM 2.0 isolates cryptographic processes like the storage and use of keys from the main CPU. This way, it helps create a secure domain for critical operations and reduces the risk of interference and manipulation. This level of isolation helps ensure that sensitive information remains protected from potential threats,” as Microsoft explains.
Security researchers at AMD have found two vulnerabilities in several AMD Ryzen CPUs. These flaws are also known as CVE-2026-6726 and CVE-2026-6727.
AMD published a security bulletin, stating that attackers with elevated privileges can exploit the vulnerabilities by sending malicious commands to TPM 2.0 chips in certain Ryzen CPUs.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
If attackers exploit these vulnerabilities, they could read data stored in the TPM chip, such as private keys. They could also disable the security chip, causing certain features, such as BitLocker, to stop functioning.
The vulnerabilities have a CVSS score of 8.5 (high) and 8.3 (high), respectively. AMD recommends updating the Platform Initialization (PI) firmware version immediately.
The Santa Clara-based tech company has been working with motherboard manufacturers for months to patch the flaws. They have since released BIOS updates that should resolve the issues.