Chipmakers Patch Over 80 Bugs, Including Severe Flaws
Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.
Chipmakers Intel and AMD each released security advisories on Tuesday, together addressing more than 80 vulnerabilities across a wide range of products, from server processors to development tools and wireless software.
Intel published 42 advisories covering 72 vulnerabilities, while AMD issued five advisories detailing a dozen flaws. The patches come as part of the companies' regular Patch Tuesday updates.
High-Severity Flaws in Intel Products
According to Intel, several high-severity vulnerabilities were patched in its PROSet/Wireless WiFi software, which could allow an attacker to escalate privileges or conduct a denial-of-service (DoS) attack.
Other high-severity issues were addressed in Xeon processors, Data Center Attestation Primitives, Alias Checking Trusted Module for Xeon processors, TDX, Active Management Technology, PROSet/Wireless WiFi software, and CSME and SPS. These flaws could lead to privilege escalation, local code execution, or denial-of-service.
Intel's Medium-Severity Fixes
Intel also patched medium-severity vulnerabilities in a variety of software products, including Transfer Learning Tool, Extension for PyTorch, LLM-on-Ray, Gaudi Container Runtime, Performance Counter Monitor, vLLM Hardware Plugin for Gaudi, Approximate Bayesian Inference Framework, Hardware Aware Automated Machine Learning, EquiTriton Software, and Workload Services Framework.
Additional medium-severity issues were resolved in LLM Scaler, LLM Library and oneCCL Bindings for PyTorch, TDX DCAP and Guest, AI Containers, Cluster Management Toolkit for Kubernetes, Open VKL, Extension for TensorFlow, NPU Drivers, Neural Compressor, Battery Life Diagnostic Tool, Xeon and Core Ultra, UEFI Reference BIOS, AI Reference Models, CSME, and SPS products. These vulnerabilities could be exploited for privilege escalation, denial-of-service, or information disclosure.
The company also fixed a low-severity vulnerability in Slim Bootloader.
AMD's Advisories Cover a Dozen Bugs
AMD's advisories describe five high-severity issues in the Vitis development environment. Exploitation of these flaws could lead to private key disclosure, privilege escalation, and arbitrary code execution.
The chipmaker also addressed arbitrary code execution issues in Ryzen Master Utility, SEV-SNP, and Power Design Manager.
Earlier This Month
Earlier this month, AMD informed customers about a Safe RET interrupt vulnerability and a recently disclosed SEV attack method dubbed PowerHooK. These are separate from the new advisories.
- Intel: 42 advisories, 72 vulnerabilities
- AMD: 5 advisories, 12 vulnerabilities
- Combined: more than 80 vulnerabilities
What This Means for Businesses
For IT teams and security professionals, the breadth of these patches underscores the importance of staying current with firmware and software updates from both chipmakers. While none of these flaws are confirmed to have been exploited in the wild, the potential impact of high-severity issues in foundational components like processors and security modules makes timely patching critical.
As chipmakers increasingly bundle hardware and software, the responsibility to keep pace with patches falls on both the vendors and the users of their products. Organizations should review the advisories and assess their exposure to these vulnerabilities.
Sources
- SecurityWeek Original source
Continue Reading
VMware vCenter Flaw Exploited for Persistent Access
Attacks exploiting CVE-2026-59310 target hundreds of victims, deploying reverse_ssh for persistent access.
Ivanti Endpoint Manager Patches Critical Flaws
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
Industrial Patch Tuesday: Critical Gaps Closed in Siemens, Schneider, Phoenix
August 2026 ICS Patch Tuesday advisories from Siemens, Schneider Electric, Phoenix Contact address critical vulnerabilities, including a maximum-severity flaw in Siemens IoT devices.