Junglewise Threat Intelligence

CVE-2026-40677: AMD Optional Tools man-in-the-middle vulnerability

CVE-2026-40677 · Severity: info · CVSS 7.7 · Published 2026-06-12

Vendors: Amd.

Executive brief

Certain optional software tools provided by AMD use unencrypted HTTP connections for communication. This allows an attacker positioned on the same network to intercept and modify data, which could result in the installation of malicious software or unauthorized control over the system. Users should update to the latest versions of these tools to ensure secure, encrypted communications are used.

Technical details

AMD optional tools utilize insecure HTTP transport instead of HTTPS for certain communications. This vulnerability allows a network-positioned attacker to perform a Man-in-the-Middle (MitM) attack. By intercepting the unencrypted traffic, an attacker can inject malicious payloads or modify data streams. Successful exploitation requires the attacker to be in a position to intercept network traffic and may require minimal user interaction, potentially leading to arbitrary code execution on the affected system. AMD has addressed this in updated versions of the affected tools.

Affected products

  • AMD Optional Tools

Timeline

  • 2026-06-12: advisory: Initial advisory published by AMD and NVD.

References

Related threats