AMD shipped the fix for these two TPM flaws in May. On a Minisforum HM80 there is still nowhere to put it
CVE-2026-6726 and CVE-2026-6727 score 8.5 and 8.3. AMD gave OEMs the Renoir mitigation on 18 May. The HM80 download page has not gained a file since February 2023.

AMD handed its OEMs the firmware that mitigates CVE-2026-6726 and CVE-2026-6727 on Ryzen 4000 Mobile parts on 18 May 2026. On 9 September an owner of a Minisforum HM80 — a 2021 mini PC built on the Ryzen 7 4800U, which is a Renoir chip — said the company had declined to ship it and suggested buying a newer machine. That is 114 days, and counting.
The complaint itself is one account. VideoCardz, which reported it, says plainly that the owner "did not provide emails that confirm it." Take the refusal as unproven, then, and look at the parts that can be checked.
AMD's bulletin can be checked.
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.
AMD scores that one 8.5 and its companion, an RSA-OAEP timing side channel, 8.3. Both are High. For Ryzen 4000 Mobile the listed mitigation is RenoirPI-FP6 1.0.0.Ee, released to OEMs on 2026-05-18, and the bulletin's instruction to users is a single sentence: "Please contact your OEM for the BIOS update specific to your product(s)."
So we did the next obvious thing and opened the page.
Minisforum's HM50/HM60/HM80 download page lists a 2021 user guide, two Windows images, a chipset driver bundle, a multimedia driver bundle, a 2021 driver package and a Wi-Fi/Bluetooth driver. No BIOS of any version. The newest file on it is dated 13 February 2023.
Which makes the refusal almost beside the point. Even a helpful support agent has nothing to send.
The honest defence runs like this. Both CVEs require a local attacker who already holds elevated privileges, so the practical risk to a home mini PC is small. The machine is five years old and out of warranty. AMD's own bulletin says the flaws are in the Trusted Computing Group's reference code rather than in AMD silicon. All fair.
And all beside the mechanism, which is the thing worth understanding here. A firmware TPM exists precisely to hold secrets against a privileged local attacker; that is the threat model it is sold for, not an edge case of it. AMD did its part: it wrote the mitigation and dated it. But AMD ships Platform Initialization firmware only to OEMs, and the OEM is the sole route to the machine. One company deciding a product is finished ends the security lifecycle of every unit it sold, and nobody has to file anything.
Notice who else AMD fixed in the same bulletin. Athlon 3000 Mobile and Ryzen 3000 Mobile, both Picasso parts from 2019, got PicassoPI-FP5 1.0.1.2f on 15 May. The chip designer is supporting silicon two years older than the box the complaint is about.
Our expectation is that no HM80 BIOS appears on that page before the end of 2026, and that AMD-SB-7064 goes on listing mitigations for dozens of consumer parts whose owners will never see them. If Minisforum posts one, we will say so and link it.
Do you own something with a fTPM in it and a vendor that has gone quiet? Check the download page before you check the CVE. The gap between the two is the actual exposure.
