Skip to content
IntelCVE-2026-20901

Intel Xeon processors: improper input validation

Medium4.0CVE-2026-20901 · Published Aug 11, 2026 · updated Aug 28, 2026

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

Intel advisory

Affected versions

PackageAffectedFixed in
Intel(R) Xeon(R) processors
Product
<= See referencesNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20

More Intel advisories

All Intel
Advisory
Intel reference platforms: information disclosure
Medium4.0Aug 11
Intel Processors: information disclosure
Medium4.0Aug 11
Intel Extension for PyTorch: unsafe deserialization
Medium4.6Aug 11
Intel Transfer Learning Tool: privilege escalation
Medium6.3Aug 11
Intel Slim Bootloader may allow an information disclosure. S: integer overflow
Low2.4Aug 11
Intel Workload Services Framework software: privilege escalation
Medium5.4Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.