Security1 distinct publisher3 min readUpdated
Forty-two Intel advisories cover privilege escalation in Xeon, TDX and CSME/SPS, plus medium-severity bugs across a wide set of AI and ML packages. AMD's five advisories add twelve more.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Forty-two Intel advisories cover privilege escalation in Xeon, TDX and CSME/SPS, plus medium-severity bugs across a wide set of AI and ML packages. AMD's five advisories add twelve more.
Follow any of these and your For You feed starts watching them — no settings page required.
Intel published 42 advisories covering 72 vulnerabilities on Tuesday, and AMD published five covering a dozen, according to SecurityWeek [2][9]. That is 84 issues between them [13], and almost none of it moves when the operating system patch cycle moves: the affected components are processor-level features, management firmware, wireless drivers, BIOS reference code, and a long tail of AI packages that engineers install themselves.
The high-severity list is where the asset inventory questions start. Intel fixed privilege escalation in Xeon processors, in the Alias Checking Trusted Module for Xeon, in TDX, and in CSME and SPS; information disclosure in Data Center Attestation Primitives; and denial of service in Active Management Technology [4]. PROSet/Wireless WiFi software appears twice in that list, once for privilege escalation and DoS and once for local code execution, privilege escalation and DoS [3][4]. Trusted execution took hits on both sides of the market: Intel patched TDX at high severity and TDX DCAP and Guest at medium [4][6], while AMD addressed arbitrary code execution in SEV-SNP [11]. AMD also disclosed a Safe RET interrupt vulnerability and a SEV attack method called PowerHooK earlier in the month, separately from Tuesday's batch [12].
The more interesting shift is what the medium-severity list now contains. Intel's two medium lists name Transfer Learning Tool, Extension for PyTorch, LLM-on-Ray, Gaudi Container Runtime, vLLM Hardware Plugin for Gaudi, Approximate Bayesian Inference Framework, Hardware Aware Automated Machine Learning, EquiTriton, Workload Services Framework, Performance Counter Monitor, LLM Scaler, LLM Library, oneCCL Bindings for PyTorch, AI Containers, Cluster Management Toolkit for Kubernetes, Open VKL, Extension for TensorFlow, NPU Drivers, Neural Compressor, Battery Life Diagnostic Tool, Xeon and Core Ultra, UEFI Reference BIOS, AI Reference Models, CSME and SPS [5][6]. At least 14 of those named products are AI, ML or accelerator-specific software rather than platform firmware [14]. SecurityWeek reports the medium-severity set can be exploited for privilege escalation, DoS and information disclosure, without mapping each impact to each product [7]. A low-severity fix landed in Slim Bootloader [8].
AMD's largest single advisory covers five high-severity issues in the Vitis development environment, with impacts described as private key disclosure, privilege escalation and arbitrary code execution [10]. Arbitrary code execution was also fixed in Ryzen Master Utility and Power Design Manager [11].
For scale, SecurityWeek's August 2026 Microsoft tally was 421 CVEs and one exploited zero-day [17]. Nothing in the chipmaker coverage reports any of these 84 as exploited in the wild [18], which is exactly why they get deferred. An earlier chipmaker round covered 70 vulnerabilities across the two vendors [16], so 84 is a normal-sized quarter, not an emergency, spread across 47 advisories that mostly do not map to a single deployment channel [15].
Three things to watch. Whether the Xeon, CSME/SPS, UEFI Reference BIOS and Slim Bootloader fixes [4][6][8] show up in OEM firmware bundles on a timeline your change window can absorb. Whether anyone in your estate can enumerate which of those AI packages [5][6] are running on developer workstations and shared training nodes. And whether the PROSet/Wireless local code execution path [4] is being tracked as an endpoint driver problem rather than a networking one.
Ranked by verification strength, evidence, and original report placement.
Intel and AMD on Tuesday announced patches for a total of more than 80 vulnerabilities across their products.
Intel has published 42 new advisories covering 72 vulnerabilities.
Intel patched several high-severity flaws in PROSet/Wireless WiFi software that could allow an attacker to escalate privileges or conduct a denial-of-service attack.
High-severity vulnerabilities were addressed in Xeon processors (privilege escalation), Data Center Attestation Primitives (information disclosure), Alias Checking Trusted Module for Xeon processors (privilege escalation), TDX (privilege escalation), Active Management Technology (DoS), PROSet/Wireless WiFi software (local code execution, privilege escalation and DoS), and CSME and SPS (privilege escalation).
Medium-severity issues have been patched by Intel in Transfer Learning Tool, Extension for PyTorch, LLM-on-Ray, Gaudi Container Runtime, Performance Counter Monitor, vLLM Hardware Plugin for Gaudi, Approximate Bayesian Inference Framework, Hardware Aware Automated Machine Learning, EquiTriton Software, and Workload Services Framework products.
Medium vulnerabilities have also been resolved in LLM Scaler, LLM Library and oneCCL Bindings for PyTorch, TDX DCAP and Guest, AI Containers, Cluster Management Toolkit for Kubernetes, Open VKL, Extension for TensorFlow, NPU Drivers, Neural Compressor, Battery Life Diagnostic Tool, Xeon and Core Ultra, UEFI Reference BIOS, AI Reference Models, CSME, and SPS products.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete vendor-sourced counts, single outlet, no CVE-level detail
All substantive facts come from one trade-press summary of the vendors' own advisories. The counts, severity tiers and affected-product lists are specific and internally consistent (72 + 12 vs 'more than 80'), which supports the core claims, but there are no CVE identifiers, CVSS scores, affected versions, attack prerequisites or independent corroboration, and the AI-tooling framing is an inference from product names rather than a sourced characterisation.
Fixes shipped by both vendors; deployment entirely unmeasured
Adoption evidence is limited to the supply side: 47 advisories with patches from Intel and AMD on the same day, plus two earlier AMD disclosures in the same month. Nothing in the supplied material indicates customer patch uptake, OEM BIOS redistribution timelines, package-manager releases for the AI tooling, or any observed exploitation that would signal urgency-driven deployment.
Slightly overstated: volume framing and AI angle rest on medium-severity items
The coverage is restrained - it makes no exploitation or emergency claims and its headline total matches the arithmetic. The mild overstatement comes from framing that leans on raw vulnerability counts as a severity proxy, and from the AI-tooling emphasis, which is real in product count but consists of medium-severity issues, while the genuinely serious items are the firmware, confidential-computing and driver privilege-escalation flaws.
No incentive or relationship disclosure in supplied material
The cluster contains a single trade-press article with no information about funding, sponsorship, vendor relationships, embargo arrangements, or commercial interests of the publisher or the vendors. Any incentive scoring would require inference beyond the supplied sources.
Facts likely accurate, significance unverified
Confidence in the numeric and product-level claims is moderate because they are concrete, checkable against vendor advisories and self-consistent. It is capped by the single-publisher cluster, the absence of CVE identifiers or severity scores, the lack of any deployment or exploitation data, and the fact that the most distinctive framing (AI tooling exposure) is derived rather than sourced.
build
Your vLLM Manifest Would Boot SGLang Too, And That Is the Problem1 distinct publisher
build
The chokepoint moved: ABF film, not lithography, now caps China's accelerator output1 distinct publisher
product
Linux 7.2 ships cache-aware scheduling, and Torvalds calls AI bug reports the new normal1 distinct publisher
build
Per-developer environments hit their ceiling the day one engineer ran five agents1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 12, 2026