Advanced Micro Devices manufactures a very broad portfolio of processors, accelerators, and server platforms spanning consumer, enterprise, and high-performance computing segments, positioning it among the most prominent vendors in the vulnerability landscape. Its vulnerability disclosures cluster heavily within the EPYC server-processor line and recur through weakness classes reflecting the complexity of modern processor design: improper input validation, boundary conditions in memory operations, and insufficient documentation of hardware behavior. A meaningful share of the vendor's CVEs reach critical severity, though the technical nature of processor-level vulnerabilities—often requiring specialized access or firmware updates rather than application-layer exploitation—shapes the practical remediation profile. Defenders tracking this vendor should prioritize advisories affecting EPYC deployments in mission-critical infrastructure, as patches frequently require coordinated firmware and BIOS updates across large server fleets; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advanced Micro Devices Inc. over time
Of all the CVEs published by Advanced Micro Devices Inc. as a CNA, 56.5% affect products that Advanced Micro Devices Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Advanced Micro Devices Inc., 85.9% are self-published by Advanced Micro Devices Inc. as a CNA.
Signals from CVEs in this vendor scope (297 CVEs).
297 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49121CRITICAL AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that al | Jun 1, 2026 | 9.8 | 39 | NO | NO |
CVE-2020-6100CRITICAL An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel shader can cause memory corruption vulnerabil | Jul 20, 2020 | 9.9 | 32 | NO | NO |
CVE-2021-26379CRITICAL Insufficient input validation of mailbox data in the
SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially
leading to a loss of integrity and privilege escalati | May 9, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-26334CRITICAL The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the | Dec 1, 2021 | 9.9 | 31 | NO | NO |
CVE-2020-6103CRITICAL An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially | Jul 20, 2020 | 9.9 | 31 | NO | NO |
CVE-2019-5049CRITICAL An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out- | Oct 31, 2019 | 10.0 | 31 | NO | NO |
CVE-2023-20591CRITICAL Improper re-initialization of IOMMU during the DRTM event
may permit an untrusted platform configuration to persist, allowing an attacker
to read or modify hypervisor memory, poten | Aug 13, 2024 | 10.0 | 30 | NO | NO |
CVE-2022-23820CRITICAL Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution. | Nov 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-46760CRITICAL A malicious or compromised UApp or ABL can send
a malformed system call to the bootloader, which may result in an out-of-bounds
memory access that may potentially lead to an attack | May 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-36333HIGH A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | May 15, 2026 | 7.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (297 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advanced Micro Devices Inc..
Media articles that mention a CVE ID that affects a product developed by Advanced Micro Devices Inc. — matched by CVE ID, not by vendor name.