CVE-2026-8810: Insyde Software INSYDEH2O, INSYDEH2O Arm

Medium severity, CVSS 6.9. EPSS: 0.1% chance of exploitation in the next 30 days.

On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.

Affected products

Published 2026-08-19. Last modified 2026-08-31.