Patch Tuesday Intel AMD is deze ronde duidelijk gericht op een stevige stapel beveiligingsupdates. Intel en AMD hebben samen patches gepubliceerd voor meer than 80 vulnerabilities in verschillende productlijnen. Daarmee pakken ze problemen aan die kunnen leiden tot onder meer privilege escalation, denial-of-service (DoS) en informatielekken.
Voor security- en infrastructuurteams komt dit vooral neer op één snelle actie: check direct welke getroffen onderdelen jullie gebruiken—van draadloze WiFi-software en platformbeheer tot server- en edge-omgevingen met Xeon en uiteenlopende acceleratie- of virtuele technologieën.
Overview: what exactly Intel and AMD patched
This week, Intel published 42 new advisories covering in total 72 vulnerabilities. AMD followed with five new advisories for together “a dozen” issues, bringing the total to more than 80 patched problems within the update window.
The vulnerabilities range from high and medium severity, with one low-severity case as well, but they affect very different components. That breadth makes it important not to focus solely on CVEs, but also on the software and hardware parts that are running in your environments.
Intel: focus on high severity in platform and network components
A portion of Intel’s attention went to high-severity issues. Multiple problems were addressed in particular in PROSet/Wireless WiFi. According to Intel, attackers could use these issues to increase privileges or launch a DoS attack.
In addition, high-severity vulnerabilities were fixed across a range of server and platform functionalities, such as:
- Xeon processors (privilege escalation)
- Data Center Attestation Primitives (information disclosure)
- Alias Checking Trusted Module for Xeon (privilege escalation)
- TDX (privilege escalation)
- Active Management Technology (DoS)
- PROSet/Wireless WiFi (local code execution, privilege escalation and DoS)
- CSME and SPS (privilege escalation)
The key point: these are not “edge cases”. The combination of platform management tools, attestation components and virtualization techniques means a flaw can impact both reliability and confidentiality.
Intel: medium-severity updates in AI, container and ML-related software
Beyond the high-severity patches, there are also medium-severity vulnerabilities fixed across multiple software components. Intel mentions, among others, products and libraries such as:
- Transfer Learning Tool
- Extension for PyTorch
- LLM-on-Ray
- Gaudi Container Runtime
- Performance Counter Monitor
- vLLM Hardware Plugin for Gaudi
- LLM Scaler and LLM Library
- oneCCL components for PyTorch (oneCCL Bindings)
Intel also reports medium-severity issues for, among other things, AI Containers, components around cluster management for Kubernetes, and various machine- or hardware-related drivers and frameworks. Updates are also mentioned for UEFI Reference BIOS, AI Reference Models, and platform parts such as CSME and SPS.
For teams working on AI infrastructure (containers, tooling around training/inference, and hardware acceleration), this is a clear reminder: the supply chain around hardware-optimized software is broad and requires structured patching.
Intel: also a low-severity issue in Slim Bootloader
Alongside the higher-severity problems, Intel also fixed a low-severity vulnerability in Slim Bootloader. Although urgency is often lower for low-severity issues, firmware- and bootloader-related software is typically something you want to drive tightly through your upgrade process.
AMD: advisories for Vitis and issues across multiple utilities
AMD published five advisories to inform customers about roughly twelve vulnerabilities. One of these advisories describes five high-severity issues in the Vitis development environment. According to AMD, exploitation could lead to private key disclosure, privilege escalation and arbitrary code execution.
In addition, AMD also addressed arbitrary code execution issues in tools and platform components such as:
- Ryzen Master Utility
- SEV-SNP
- Power Design Manager
It once again sets the tone for development and operations environments: it’s not only “runtime” software that matters, but also the tooling you use to build, manage systems or leverage hybrid security features.
Impact types: why this is more than just standalone CVEs
Intel states that the gaps can be exploited for privilege escalation, DoS and information disclosure. In practice, this means attackers may be able to:
- obtain higher privileges to perform additional actions;
- disrupt services or make components unusable;
- leak data that affects trust or compliance.
That’s why it’s wise to tie your patch planning to your system inventory: which servers, endpoints, containers and hardware-acceleration stacks are running, and which components exactly fall under the software products mentioned?
What can you do now? A quick checklist for administrators
To reduce the risks from Patch Tuesday Intel AMD quickly, a pragmatic approach helps:
- Inventory which Intel and AMD products/software components you use, including platform management, WiFi software and AI/tooling.
- Prioritize by impact: start with high-severity components such as WiFi PROSet/Wireless, Xeon-related parts and TDX/attestation functionality.
- Plan firmware and platform updates (such as bootloader and platform management components) according to your change windows.
- Re-evaluate after patching: verify that services remain stable and that any security functions still work correctly.
If your patch policy goes beyond OS updates, this is an extra reason to also include hardware and accelerator software in your regular management cycle.
Related updates to include in the same patch cycle
Patch Tuesday often touches multiple layers at once. When you build your update plan for this round, it can help to also look at recent issues from other vendors or sectors. For example:
- ICS Patch Tuesday: fixes from Siemens, Schneider and Phoenix for environments with industrial systems.
- August 2026 Patch Tuesday: focus on Microsoft fixes when your patch planning also impacts OS and application layers.
- LiteLLM supply chain attack: 2,500 organizations affected if you’re mapping supply chain risks for AI tooling.
Conclusion
Patch Tuesday Intel AMD delivers more than 80 security fixes in total this round, with Intel as the largest contributor. The high-severity issues in PROSet/Wireless WiFi and in various server and platform components deserve quick attention in particular. At the same time, the updates in AI and container-related tooling show that modern infrastructure requires patching all the way through the software layers tied to hardware and acceleration chains.
Approach it in a structured way: inventory, prioritize, update and verify. That way you prevent vulnerabilities from lingering in the lower part of your stack—exactly where attackers often try to enter.
Source: https://www.securityweek.com/chipmaker-patch-tuesday-intel-amd-fix-over-80-vulnerabilities-combined/
