Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trustedfirmware

First CVE: Nov 2, 2015Active for: 11 yearsTotal CVEs: 84
47.6
VTI Score
High

Trusted Firmware maintains a narrowly scoped but critically positioned portfolio centered on Trusted Firmware-M, a reference implementation for secure firmware and trusted execution environments that underpins security infrastructure across embedded systems and IoT devices. Despite modest product breadth, this vendor occupies an exceptionally prominent position in the vulnerability landscape due to the foundational role trusted firmware plays in hardware security boundaries. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including out-of-bounds reads and writes, integer overflows, and buffer overflows that are characteristic of low-level memory-unsafe code operating in privileged execution contexts. The exposure also reflects cryptographic algorithm choices and implementation details that warrant scrutiny in security-critical code. Defenders tracking embedded and IoT deployments should monitor this vendor's advisories closely, as firmware updates often depend on device manufacturers and may propagate slowly; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
84
Total CVEs
More Total CVEs than 99% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
1.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Trustedfirmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2015
10 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (84 CVEs).

84 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27562MEDIUM
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under t
May 25, 20215.556YESNO
CVE-2026-40290HIGH
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in versio
Jun 3, 20267.834NONO
CVE-2026-34875CRITICAL
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
Apr 1, 20269.833NONO
CVE-2019-1010298CRITICAL
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed ver
Jul 15, 20199.833NONO
CVE-2026-34877CRITICAL
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who
Apr 2, 20269.832NONO
CVE-2021-44732CRITICAL
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
Dec 20, 20219.831NONO
CVE-2019-1010293CRITICAL
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.
Jul 15, 20199.831NONO
CVE-2026-33662HIGH
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10
Apr 24, 20267.530NONO
CVE-2019-1010292CRITICAL
Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is:
Jul 16, 20199.830NONO
CVE-2019-1010295CRITICAL
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed ver
Jul 15, 20199.830NONO
View all 84 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products84 CVEs
8%
36%
35%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local27 (32.1%)
Network50 (59.5%)
Unknown2 (2.4%)
Physical5 (6.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low61 (72.6%)
High21 (25.0%)
Unknown2 (2.4%)
User Interaction
None78 (92.9%)
Unknown2 (2.4%)
Required4 (4.8%)
Privileges Required
Low22 (26.2%)
High3 (3.6%)
None57 (67.9%)
Unknown2 (2.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (84 CVEs).

CISA KEV
1 CVE
1.2% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trustedfirmware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trustedfirmware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trustedfirmware's Products

View all 6 CNAs →

Top CWEs