Subscribe
18:00Tao calls OpenAI’s Navier–Stokes push “resource extraction”17:10LAPTOP memecoin hits $190.81, then loses 99% inside an hour17:05Hubinger puts the odds of AI killing everyone above 10%; a colleague resigns16:39CancerBench launches; five frontier models tied at zero cancer types cured16:30ElevenLabs preparing 2028 IPO after $11bn round, The Information reports16:30Anthropic retracts its July explanation: Mythos 5 attacked systems knowingly
Hardware3 min read

AMD shipped the fix for these two TPM flaws in May. On a Minisforum HM80 there is still nowhere to put it

CVE-2026-6726 and CVE-2026-6727 score 8.5 and 8.3. AMD gave OEMs the Renoir mitigation on 18 May. The HM80 download page has not gained a file since February 2023.

In briefAMD lists RenoirPI-FP6 1.0.0.Ee as the mitigation for Ryzen 4000 Series Mobile processors, released 2026-05-181AMD scores CVE-2026-6726 at 8.5 High and CVE-2026-6727 at 8.3 High2AMD directs affected users to their OEM for the BIOS update3
A Minisforum mini PC on a desk
Photo: Goovaeh8fot6yugh (CC0)

AMD handed its OEMs the firmware that mitigates CVE-2026-6726 and CVE-2026-6727 on Ryzen 4000 Mobile parts on 18 May 2026. On 9 September an owner of a Minisforum HM80 — a 2021 mini PC built on the Ryzen 7 4800U, which is a Renoir chip — said the company had declined to ship it and suggested buying a newer machine. That is 114 days, and counting.

The complaint itself is one account. VideoCardz, which reported it, says plainly that the owner "did not provide emails that confirm it." Take the refusal as unproven, then, and look at the parts that can be checked.

AMD's bulletin can be checked.

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.
AMD security bulletin AMD-SB-7064, CVE-2026-6726

AMD scores that one 8.5 and its companion, an RSA-OAEP timing side channel, 8.3. Both are High. For Ryzen 4000 Mobile the listed mitigation is RenoirPI-FP6 1.0.0.Ee, released to OEMs on 2026-05-18, and the bulletin's instruction to users is a single sentence: "Please contact your OEM for the BIOS update specific to your product(s)."

So we did the next obvious thing and opened the page.

Minisforum's HM50/HM60/HM80 download page lists a 2021 user guide, two Windows images, a chipset driver bundle, a multimedia driver bundle, a 2021 driver package and a Wi-Fi/Bluetooth driver. No BIOS of any version. The newest file on it is dated 13 February 2023.

Files on the Minisforum HM50/HM60/HM80 download page, by year
202132022220232202402025020260

Which makes the refusal almost beside the point. Even a helpful support agent has nothing to send.

The honest defence runs like this. Both CVEs require a local attacker who already holds elevated privileges, so the practical risk to a home mini PC is small. The machine is five years old and out of warranty. AMD's own bulletin says the flaws are in the Trusted Computing Group's reference code rather than in AMD silicon. All fair.

And all beside the mechanism, which is the thing worth understanding here. A firmware TPM exists precisely to hold secrets against a privileged local attacker; that is the threat model it is sold for, not an edge case of it. AMD did its part: it wrote the mitigation and dated it. But AMD ships Platform Initialization firmware only to OEMs, and the OEM is the sole route to the machine. One company deciding a product is finished ends the security lifecycle of every unit it sold, and nobody has to file anything.

Notice who else AMD fixed in the same bulletin. Athlon 3000 Mobile and Ryzen 3000 Mobile, both Picasso parts from 2019, got PicassoPI-FP5 1.0.1.2f on 15 May. The chip designer is supporting silicon two years older than the box the complaint is about.

Our expectation is that no HM80 BIOS appears on that page before the end of 2026, and that AMD-SB-7064 goes on listing mitigations for dozens of consumer parts whose owners will never see them. If Minisforum posts one, we will say so and link it.

Do you own something with a fTPM in it and a vendor that has gone quiet? Check the download page before you check the CVE. The gap between the two is the actual exposure.

Sources

01
AMD lists RenoirPI-FP6 1.0.0.Ee as the mitigation for Ryzen 4000 Series Mobile processors, released 2026-05-18AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726 (non-AMD) RenoirPI-FP6 1.0.0.Ee (AMD fTPM) 2026-05-18 CVE-2026-6727 (non-AMD) RenoirPI-FP6 1.0.0.Ee (AMD fTPM) 2026-05-18” — amd.com · primary · Sep 10
02
AMD scores CVE-2026-6726 at 8.5 High and CVE-2026-6727 at 8.3 HighCVE-2026-6726 (non-AMD) An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key ...…” — amd.com · primary · Sep 10
03
AMD directs affected users to their OEM for the BIOS updateAMD recommends updating to the Platform Initialization (PI) firmware version indicated below (note the PI firmware versions were released by AMD to the Original Equipment Manufacturers (OEM) on the dates listed below). Please contact…” — amd.com · primary · Sep 10
Show all 9 sources
04
AMD believes firmware TPMs on AMD platforms are impacted, and the vulnerability originates in the TCG TPM 2.0 reference implementationThe Trusted Computing Group (TCG) Vulnerability Response Team (VRT) has reported a potential out of bounds (OOB) read vulnerability in the Trusted Platform Module (TPM) 2.0 reference implementation code. ... AMD has analyzed the Trusted…” — amd.com · primary · Sep 10
05
AMD shipped mitigations for Athlon 3000 and Ryzen 3000 Mobile (Picasso) on 2026-05-15AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726 (non-AMD) PicassoPI-FP5 1.0.1.2f (AMD fTPM) 2026-05-15 ... AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics CVE-2026-6726 (non-AMD) PicassoPI-FP5…” — amd.com · primary · Sep 10
06
A Minisforum HM80 owner says the company refused a BIOS security update and suggested buying a newer system; VideoCardz notes the owner did not provide confirming emailsAn HM80 owner claims the company refused to provide a firmware update containing AMD's newer security fixes and instead suggested purchasing a newer system. The user did not provide emails that confirm it, though. The HM80 launched in…” — videocardz.com · reported · Sep 10
07
VideoCardz reports the support exchange ran to roughly 14 to 15 emails and that the HM50/HM60/HM80 support page lists no BIOS downloadAccording to the HM80 owner, the exchange with Minisforum support lasted around 14 to 15 emails. The user claims support initially treated the request as a performance-related BIOS update, recommended buying a newer model and later cited…” — videocardz.com · reported · Sep 10
08
Minisforum's HM50/HM60/HM80 download page lists seven files, none of them a BIOS, with the newest dated 13 February 2023HM50/HM60/HM80 Download ... User Guide Windows10 5.52M 07/13/2021 PDF | Windows10_Pro_20H2 OS 10.55 GB 08/17/2021 RAR | Windows11_Pro OS 10.93GB 04/20/2022 RAR | AMD Ryzen™ and Athlon™ Mobile (Chipset) Drivers Windows10/11 - 2/13/2023 |…” — minisforum.net · primary · Sep 10
09
VideoCardz published the report on 9 September 2026Minisforum HM80 owner says company refused BIOS security update, suggested buying a new PC” — x.com · primary · Sep 10
Up next · Keep readingHardware · 3 min read

A20 Pro is the first 2nm phone chip. The number that matters is 32 Neural Engine cores after three years at 16

Apple doubled the Neural Engine, widened memory bandwidth 50 percent, moved the DRAM off the thermal path and tripled the vapor chamber. Every one of those decisions is about running models on the phone.

Continue ↓