CVE-2026-54467CWE-283

CVE-2026-54467

High · published August 26, 2026

CVSS v3.1
7.0
EPSS
0%
Percentile
4.5
In the wild
Unconfirmed
What it is

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

The record
Technical detail
CVSS v3.1
7.0 · HIGH
Vector
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00150 · 4.5th percentile
Weakness
CWE-283 · Unverified Ownership
Published
2026-08-26T09:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 06:36Z
    EPSS moved — → 0%
    epss
  • 26 AUG 04:03Z
    On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated…
    cvelistv5