# TPM 2.0 reference flaws enable forged attestations

Published: 2026-08-11 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/5c52c6ed-7496-5b61-a5b1-d4e4010614d5/tpm-2-0-reference-flaws-enable-forged-attestations

> Two TPM 2.0 reference implementation vulnerabilities allow privileged local attackers to decrypt RSA-protected data and forge TPM attestations.

CERT/CC disclosed two vulnerabilities in the Trusted Computing Group's TPM 2.0 reference implementation, discovered by Intel researchers and coordinated with the TCG Vulnerability Response Team. CVE-2026-6727 is a timing side-channel in RSA OAEP decryption that could let a privileged local attacker recover plaintext from ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), potentially exposing import blobs, credential blobs, and session salts. CVE-2026-6726 is an information leakage flaw that could allow an attacker to obtain credentials for falsified TPM keys (such as Attestation Keys, DevID keys, or TLS authentication keys) from a TPM-aware CA, enabling forged TPM 2.0 attestations.

Both issues require privileged local access to the TPM command interface, limiting exploitation to attackers who already have significant access to the target system or hypervisor. However, successful exploitation undermines the trust chain that TPM-based attestation and key management provide, potentially allowing an attacker to present forged hardware-backed identity or measurements as legitimate. This has downstream implications for remote attestation, device identity (DevID), and secure boot trust models across discrete TPMs, firmware TPMs, and software/virtual TPM implementations used in cloud environments.

Multiple vendors have incorporated fixes from the updated TPM 2.0 reference implementation into firmware and software releases. Affected organizations should apply TPM firmware updates, OS patches, or vendor-supplied software updates, and cloud customers using software-based TPMs should consult their provider regarding remediation status.

## Mentioned in this report

- Vulnerabilities: CVE-2026-6726, CVE-2026-6727

Source reporting: https://kb.cert.org/vuls/id/431093

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5c52c6ed-7496-5b61-a5b1-d4e4010614d5/tpm-2-0-reference-flaws-enable-forged-attestations.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
