CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [medium] Intel UEFI Reference BIOS: Vulnerability enables disclosure of information

mediumCVE-2026-20712
A local attacker can exploit a vulnerability in Intel UEFI Reference BIOS to disclose information.

CSIRTS triage

What
Local attacker can disclose information via vulnerability in UEFI Reference BIOS.
Who is affected
Systems using Intel UEFI Reference BIOS with local attacker access.
Urgency
Medium severity limited to local access; apply BIOS updates within standard patch cycles.
Action
Update BIOS firmware to patched version addressing CVE-2026-20712.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch UEFI Reference BIOS

Get an email when a new UEFI Reference BIOS advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
medium
Published
2026-08-18
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2757

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-20712coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CERT-Bund (BSI) Security Advisories