CVE-2026-6484
Awaiting Analysis Awaiting Analysis - Queue

Arbitrary Code Execution in UEFI Firmware

Vulnerability report for CVE-2026-6484, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-31

Assigner: Insyde

Description

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
insyde insydeh2o 8.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1277 The product does not provide its users with the ability to update or patch its firmware to address any vulnerabilities or weaknesses that may be present.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in UEFI firmware (InsydeH2O 8.2) occurs due to lack of verified boot for certain firmware volumes. This allows arbitrary code execution because the system fails to verify the authenticity of firmware data before loading it.

Detection Guidance

Detection requires checking firmware versions and verifying boot integrity. Inspect InsydeH2O firmware versions using system tools or manufacturer utilities. Compare against patched versions listed in Insyde's advisory SA-2026003. Use firmware update tools to check for available patches. Monitor system logs for unauthorized code execution attempts during boot.

Impact Analysis

An attacker could exploit this to execute malicious code on your system at a high privilege level. This could lead to system compromise, data theft, or installation of persistent malware even if the OS is reinstalled.

Compliance Impact

The vulnerability allows arbitrary code execution due to lack of verified boot in firmware volumes, which could lead to unauthorized access or modification of sensitive data. This may violate compliance requirements for data integrity and protection under standards like GDPR and HIPAA, as unauthorized code execution could result in data breaches or loss of confidentiality.

Mitigation Strategies

Apply firmware updates provided by Insyde Software for InsydeH2O 8.2 to ensure verified boot for all firmware volumes. Check if your Intel platform (Arrow Lake, Raptor Lake, Meteor Lake) is affected and update accordingly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6484. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart