CVE-2026-33197
AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.
- Published Sep 8, 2026
- CVSS 8.7 high
- 0.2% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot CERT Coordination Center ·