LiveActive security incident?Get immediate response
CVE Record

CVE-2021-26390: A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potential...

A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This AMD issue affects some Ryzen and Athlon platforms. If a malicious or already-compromised UApp or ABL can influence the bootloader, it may cause arbitrary memory corruption and undermine data integrity during boot-related operations.

Executive priority

Track this as a firmware integrity risk, but avoid emergency claims without model-specific exposure or exploitation evidence. Prioritize inventory correlation and vendor firmware guidance for AMD Ryzen and Athlon fleets.

Technical view

CVE-2021-26390 describes a bootloader memory-corruption condition where a malicious or compromised UApp or ABL may coerce corruption of arbitrary memory. Public source data names AMD Ryzen and Athlon Series as affected in various versions, but does not provide CVSS, CWE, exact models, or patch details.

Likely exposure

Exposure appears limited to AMD Ryzen and Athlon systems in the affected families, with exact platform and version scope unresolved in the supplied data. Organizations need OEM and AMD bulletin correlation before declaring assets affected.

Exploitation context

The source bundle does not show CISA KEV listing or cited evidence of active exploitation. The described prerequisite is a malicious or compromised UApp or ABL, which suggests exploitation depends on prior compromise or control of a trusted boot component.

Researcher notes

The public bundle is sparse: no CVSS vector, CWE, exact versions, exploit status, or fix version is supplied. Analysis should remain anchored to AMD SB-1027 and CVE records until platform-specific details are verified.

Mitigation direction

  • Inventory AMD Ryzen and Athlon systems.
  • Review AMD SB-1027 and OEM advisories for exact affected platforms.
  • Apply only vendor-provided BIOS or firmware updates when listed for your model.
  • Prioritize systems with firmware integrity concerns or sensitive workloads.
  • Monitor AMD and OEM guidance for missing patch details.

Validation and detection

  • Map CPU family and system model to AMD and OEM affected lists.
  • Record current BIOS and firmware versions for each candidate system.
  • Compare installed firmware against vendor guidance for CVE-2021-26390.
  • Review scanner findings against hardware inventory before remediation decisions.
  • Escalate unexplained bootloader or firmware integrity alerts for investigation.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-26390 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AMDRyzen™ SeriesvariousListed
AMDAthlon™ SeriesvariousListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.