SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-54467

HIGH · CVSS 7 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Trusted Firmware-M (TF-M) platform versions 2.0.0 to 2.3.0, where improper mailbox initialization on PSOC64 and RP2350 allows for the acceptance of a non-secure, unvalidated pointer. This flaw could lead to unauthorized access or manipulation of memory, potentially compromising the integrity and confidentiality of the system. Organizations utilizing TF-M on the specified hardware should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-54467
Severity
HIGH
CVSS
7
EPSS
0.15%

Original NVD Description

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.