AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-20901

MEDIUM · CVSS 4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Certain Intel Xeon processors are vulnerable due to improper input validation in their firmware, which could allow an attacker with local access to escalate privileges and alter data. This vulnerability requires a high complexity attack and the presence of a privileged user, but does not necessitate user interaction or special internal knowledge. Organizations using affected Intel Xeon processors should prioritize patching this vulnerability to mitigate the risk of potential data integrity issues.

CVE
CVE-2026-20901
Severity
MEDIUM
CVSS
4
EPSS
0.10%

Original NVD Description

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.