Man-in-the-Middle (MitM) attack in AMD products - CVE-2026-40677
Published: June 22, 2026
Vulnerability identifier: #VU135012
CSH Severity: High
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40677
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.
The vulnerability exists due to use of insecure HTTP transport within AMD optional tools. A remote attacker can perform a man-in-the-middle (MitM) attack and execute arbitrary code on the target system.
Affected software
AMD Ryzen Master
AMD µProf
AMD Management Console (AMC)
AMD µProf
AMD Management Console (AMC)
How to mitigate CVE-2026-40677
Install updates from vendor's website.
AMD Ryzen Master - update to 2.14.3
AMD µProf - update to 5.3
AMD Management Console (AMC) - update to 14.0.0
AMD µProf - update to 5.3
AMD Management Console (AMC) - update to 14.0.0