Skip to main content

CISA issues update on TPM 2.0 reference vulnerabilities CVE-2026-6726 and CVE-2026-6727

The Trusted Platform Module (TPM) 2.0 reference implementation contains two vulnerabilities that can enable unauthorized access to information or decryption capability through interactions with a TPM command interface. One issue involves information leakage tied to falsified TPM keys, and the other is a timing side-channel in RSA OAEP decryption, with potential effects that include decrypting data tied to TPM-managed RSA keys or enabling fraudulent TPM 2.0 attestations.

Two vulnerabilities are identified in the TPM 2.0 reference implementation: CVE-2026-6726, described as information leakage via falsified TPM keys, and CVE-2026-6727, described as a timing side-channel vulnerability in RSA OAEP decryption. A privileged local attacker with access to the TPM command interface may exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts; under certain conditions, this may also enable forgery of TPM 2.0 attestations. For CVE-2026-6726, a privileged local attacker may obtain credentials from a TPM-aware Certificate Authority (CA) for a falsified TPM key, such as an Attestation Key (AK), DevID key, or TLS authentication key, enabling creation of fraudulent TPM 2.0 attestations using the forged key. Both vulnerabilities require privileged access to the TPM command interface.

Successful exploitation requires privileged local access to a TPM command interface. Depending on the vulnerability exploited, an attacker may be able to decrypt ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including credential blobs, import blobs, and session salts; obtain credentials for falsified TPM keys; and produce fraudulent TPM 2.0 attestations that appear to originate from a legitimate TPM. The overall impact depends on the affected TPM implementation and how TPM-based attestation and key management are used by the platform.

The vulnerabilities originate in the TPM 2.0 reference implementation, and TPM vendors have incorporated the corresponding fixes into updated firmware and software releases. Users should install TPM firmware updates, operating system updates, or software patches provided by their platform or TPM vendor. Cloud providers using software-based TPM implementations may also have deployed updates, and customers should consult their cloud provider's guidance to determine whether any additional action is required.

Two TCG advisories document these vulnerabilities: TCGVRT010 and TCGVRT0011. The report also notes acknowledgements to security researchers Liran Perez, Zecharye Galitzky, Shai Sarfati, and Yanai Moyal from Intel for reporting the vulnerabilities, and to members of the Trusted Computing Group’s Vulnerability Response Team, TCG VRT, for working with CERT/CC toward a multi-party vulnerability disclosure.

The original article was written by Decision Insights Editorial.