Insyde's Security Pledge
Recent Security Advisories

INSYDE-SA-2026003
Product
CVSS Score
Original Date
Last Revised
InsydeH2O
8.2
2026-08-11
Summary
Lack of verified boot to certain FV may cause arbitrary code execution.
Vulnerability Details
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
https://www.cve.org/CVERecord?id=CVE-2026-6484
Description: In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
CWE-1277: Insufficient Verification of Data Authenticity in Firmware
Solution Information
Intel Mobile Platforms:
Panther Lake: Unaffected
Lunar Lake: Unaffected
Aarow Lake H/U: Version 05.56.17.0022
Aarow Lake S/HX: Version 05.56.17.0037
Rapter Lake: Version 05.47.24.0058
Twin Lake: Version 05.44.45.0029
Intel Server/Embedded platforms:
Whitley (CLX/CPX/ICX): Trunk
CedarIsland (CPX): Trunk
Eagle Stream: Unaffected
Birch Stream: Unaffected
Mehlow/Mehlow-R(CFL-S): Unaffected
Tatlow (RKS): Unaffected
Jacobsville(SNR): Trunk
Idaville: Trunk
Kaseyville: Unaffected
Whiskey Lake: Trunk
Come tLake-S: Unaffected
Tiger Lake UP3/H: Unaffected
Alder Lake: Version 05.47.24.2057
Raptor Lake: Version 05.47.24.0057
Meteor Lake – U/H ARL-H/U: Version 05.56.07.0022
Meteor Lake – PS ARL-H/U: Version 05.56.07.0022
Arrow Lake – S ARL-S/HX: Version 05.55.45.0036
Arrow Lake – U/H ARL-H/U: Version 05.56.07.0022
Elkhart Lake: Version 05.48.17.0030
Alder Lake N: Trunk
Amston Lake: Trunk
Twin Lake: Trunk
Acknowledgements
Thanks to Nikolaj Schlej, independent firmware security researcher, for reporting the vulnerability and engaging in this coordinated disclosure.
Revision History
Revision #
Date
Description
1
2026-08-11
Initial Release