Trusted Firmware maintains a narrowly scoped but critically positioned portfolio centered on Trusted Firmware-M, a reference implementation for secure firmware and trusted execution environments that underpins security infrastructure across embedded systems and IoT devices. Despite modest product breadth, this vendor occupies an exceptionally prominent position in the vulnerability landscape due to the foundational role trusted firmware plays in hardware security boundaries. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including out-of-bounds reads and writes, integer overflows, and buffer overflows that are characteristic of low-level memory-unsafe code operating in privileged execution contexts. The exposure also reflects cryptographic algorithm choices and implementation details that warrant scrutiny in security-critical code. Defenders tracking embedded and IoT deployments should monitor this vendor's advisories closely, as firmware updates often depend on device manufacturers and may propagate slowly; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trustedfirmware over time
Signals from CVEs in this vendor scope (84 CVEs).
84 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27562MEDIUM In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under t | May 25, 2021 | 5.5 | 56 | YES | NO |
CVE-2026-40290HIGH OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in versio | Jun 3, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-34875CRITICAL An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. | Apr 1, 2026 | 9.8 | 33 | NO | NO |
CVE-2019-1010298CRITICAL Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed ver | Jul 15, 2019 | 9.8 | 33 | NO | NO |
CVE-2026-34877CRITICAL An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who | Apr 2, 2026 | 9.8 | 32 | NO | NO |
CVE-2021-44732CRITICAL Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. | Dec 20, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-1010293CRITICAL Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4. | Jul 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2026-33662HIGH OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10 | Apr 24, 2026 | 7.5 | 30 | NO | NO |
CVE-2019-1010292CRITICAL Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is: | Jul 16, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-1010295CRITICAL Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed ver | Jul 15, 2019 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (84 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trustedfirmware.
Media articles that mention a CVE ID that affects a product developed by Trustedfirmware — matched by CVE ID, not by vendor name.