CVE-2026-54467CWE-283
CVE-2026-54467
High · published August 26, 2026
What it is
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
The record
Technical detail
- CVSS v3.1
- 7.0 · HIGH
- Vector
- CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00150 · 4.5th percentile
- Weakness
- CWE-283 · Unverified Ownership
- Published
- 2026-08-26T09:18Z
References (2)
EPSS history
Timeline