Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-6726

Опубликовано: 11 авг. 2026
Источник: msrc
CVSS3: 7.9
EPSS Низкий

Описание

MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse

CVE-2026-6726 is a Spoofing vulnerability in the TPM 2.0 reference implementation involving improper object-slot reuse. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability.

Please see CVE-2026-6726 for more information.

FAQ

Do I need to do anything additional in order to be protected from this vulnerability?

Yes, you will need to install the following packages:

  • Windows 11 Enterprise, versions 25H2 and 24H2: KB5123607
  • Windows 11 Enterprise, versions 25H2 and 24H2 — Additional update for devices where the Pluton security processor has been configured as the TPM: KB5123273 (restart required)
  • Windows Server 2022: KB5123303 (restart required)

Обновления

ПродуктСтатьяОбновление
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for x64-based Systems
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows 10 Version 21H2 for 32-bit Systems
Windows 10 Version 21H2 for ARM64-based Systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 12%
0.00215
Низкий

7.9 High

CVSS3

Связанные уязвимости

CVSS3: 7.9
ubuntu
21 день назад

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

CVSS3: 7.9
nvd
21 день назад

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

CVSS3: 7.9
debian
21 день назад

An information leakage vulnerability was reported in the TCG TPM 2.0 r ...

CVSS3: 7.9
github
21 день назад

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

EPSS

Процентиль: 12%
0.00215
Низкий

7.9 High

CVSS3