PULSE
LIVE22signals / 24h
FEED
ransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkrybit reclama a Vibonum Technologies Private Limited · IN · Technologyransomakira reclama a Kruse Construction · Constructionransomakira reclama a University Sprinkler Systems · Business Servicesransombooba project reclama a Pelli Clarke Pelli Architects · US · Business Servicesransomdragonforce reclama a Koshkaryan Law Group · US · Business Servicesransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkrybit reclama a Vibonum Technologies Private Limited · IN · Technologyransomakira reclama a Kruse Construction · Constructionransomakira reclama a University Sprinkler Systems · Business Servicesransombooba project reclama a Pelli Clarke Pelli Architects · US · Business Servicesransomdragonforce reclama a Koshkaryan Law Group · US · Business Services
← All CVEs
CVE WatchJul 15, 2026

CVE-2025-54518

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instruction

CVSS

7.0

High

EPSS

0.3%

p17

KEV

Exploit Today

5

0-100

Published: May 15, 2026 · Last modified: Jul 15, 2026 · CWE-1189 · CWE-1220

EPSS · 30d
0.3%EPSS · 30 days0.3%
2026-06-302026-07-21
Technical description

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-505028.0 HIG
45.4%
14Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.7d
CVE-2026-504057.8 HIG
11.9%
4Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.2d
CVE-2026-561557.8 HIG
30.3%
KEV59Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability 7d
CVE-2026-550067.8 HIG
12.5%
4Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.8d
CVE-2026-491707.8 HIG
84.9%
25Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.6d
CVE-2026-485817.8 HIG
12.4%
4Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.8d