CVE Tools

CVE-2026-6727

CVE-2026-6727

No known exploitation. EPSS puts it in the 4th percentile. No fix published yet.

Published Updated Sources: CVE.org, NVD

What to do

No fixed build or workaround is published yet. Limit exposure and watch for a patch.

Steps

Written by AI from the record
  1. Check whether your systems use TPM 2.0 and whether any software or service has high local privileges and direct access to the TPM command interface (for example, local agents, management tools, or custom apps that talk to the TPM).
  2. Inventory who (and what processes) can run with administrative or equivalent local rights on TPM-enabled machines, and immediately remove/limit those capabilities where possible.
  3. Review endpoint protections: ensure EDR/antivirus are enabled and that privileged account access is tightly controlled (least privilege, strong MFA where supported).
  4. Ask your TPM/firmware/OS vendor for the status of CVE-2026-6727 and whether any mitigation or firmware update is available; if no fix exists yet, follow the vendor’s recommended hardening steps.
  5. If you cannot quickly confirm a fix, treat this as a hardening-first issue: restrict direct TPM access paths and monitor for suspicious local processes performing TPM operations repeatedly (especially abnormal RSA OAEP decryption behavior).

What it is

From the CVE record

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.

In plain language

Written by AI from the record

CVE-2026-6727 is a timing weakness in TPM 2.0 that could let a highly privileged local attacker figure out secrets or forge TPM proof in specific cases; most small businesses should worry mainly if they have an insider or malware already running with high local privileges and can directly use the TPM.

CVE-2026-6727 is a timing side-channel (CWE-208) in the TPM 2.0 RSA OAEP decryption implementation; a privileged local attacker with access to the TPM command interface could use timing observations to recover sensitive material and, under certain conditions, enable decryption of TPM-managed RSA key data and potentially forge TPM 2.0 attestations.

If you're affected

  • TPM secret recovery
  • TPM attestation forgery
  • Bypass hardware trust checks
  • Compromise authentication flows

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS4th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

0.2% chance of exploitation activity in the next 30 days, which ranks it in the 4th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

7 events over 28 days, from the signal feeds we watch.

  1. Record updated
  2. OpenVAS check added
  3. Record updated
  4. Publishedweakness classified, record updated, record updated

Affected products

Technical detail

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Scored 5.9 by NVD.

How it is reached

  • Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
  • Attack Complexity HighRequires specific conditions like a race condition or non-default configuration
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope ChangedThe exploit can affect other components (e.g. sandbox escape, host compromise from VM)

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity NoneNo integrity impact
  • Availability NoneNo availability impact

Weaknesses

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for TPM2.0, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store