CVE-2026-54467: Trustedfirmware Trusted Firmware-M

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

Affected products

Published 2026-08-26. Last modified 2026-09-09.