CVE-2026-6727

Microsoft — MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

Patch Tuesday

What EVULNABLE says

EVULNABLE Risk · priority 10/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
Patch Tuesday

Why it matters: CVSS base score 5.9, and Microsoft Exploitability Index: Exploitation Less Likely.

Scheduled Maintenance

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

Published measurements for CVE-2026-6727
MeasureValueSource
CVSS base score 5.9
FIRST EPSS 0.002 (10.2nd pctl) FIRST
Actively exploited Not confirmed Patch Tuesday
Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.