CVE-2026-6727: MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability
CVE-2026-6727 is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see CVE-2026-6727 for more information.
CSIRTS triage
- What
- Timing side-channel vulnerability in RSA OAEP implementation enables cryptographic key recovery.
- Who is affected
- Attackers with physical or local access to systems using TPM 2.0 for cryptographic operations.
- Urgency
- Medium severity (CVSS 5.9); requires controlled environment but compromises encryption security.
- Action
- Apply TPM 2.0 firmware and Windows updates addressing the timing side-channel.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch TPM 2.0 reference implementation
Get an email when a new TPM 2.0 reference implementation advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6727
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-67270.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-6727 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for MITRE
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-6726: MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reusemsrc · 2026-08-11
More from Microsoft Security Response Center
- highCVE-2026-70130: Microsoft Office Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-70354: .NET Core Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-68792: Microsoft Office Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-66807: Microsoft Office Graphics Component Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11