Serial Number: AV26-813
Date: August 13, 2026
As of August 11, 2026, AMD is affected by vulnerabilities in the following products:
- AMD Power Design Manager (PDM) Software Installer for Windows
- all except 2026.1
- AMD Power Design Manager (PDM) Software Un-Installer
- all except 2026.1
- AMD Ryzen Master
- all except 3.0.0.4199
- all except 3.1.1.5502
- AMD Ryzen Master (AMD Ryzen 3000 Series Processors)
- all except 2.14.3.5040
- AMD Ryzen Master Monitoring SDK
- all except 3.1.1.5478
- AMD Ryzen Master SDK
- all except 3.0.1.4732
- Vitis Libraries - Security Module
- all except 2026.1
- Vitis Embedded Single File Download (SFD) for Windows
- all except 2026.1
- Vitis Unified Installer for FPGAs & Adaptive SoCs in Windows
- all except 2026.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Facts Only
Serial Number: AV26-813.
Date: August 13, 2026.
Affected products include AMD Power Design Manager (PDM) Software Installer for Windows, excluding version 2026.1.
Affected products include AMD Power Design Manager (PDM) Software Un-Installer, excluding version 2026.1.
Affected product includes AMD Ryzen Master, excluding versions 3.0.0.4199 and 3.1.1.5502.
Affected product includes AMD Ryzen Master (AMD Ryzen 3000 Series Processors), excluding version 2.14.3.5040.
Affected product includes AMD Ryzen Master Monitoring SDK, excluding version 3.1.1.5478.
Affected product includes AMD Ryzen Master SDK, excluding version 3.0.1.4732.
Affected product includes Vitis Libraries - Security Module, excluding version 2026.1.
Affected product includes Vitis Embedded Single File Download (SFD) for Windows, excluding version 2026.1.
Affected product includes Vitis Unified Installer for FPGAs & Adaptive SoCs in Windows, excluding version 2026.1.
Executive Summary
Full Take
The pattern observed is a cascading notification of systemic risk across an ecosystem of specialized developer and system management tools. The aggregation of specific software components—ranging from driver installers (PDM), system monitoring utilities (Ryzen Master), and high-level development environments (Vitis)—indicates that the vulnerability exposure is not isolated to a single application but targets the foundational layers of system configuration and development workflows. The consistent exclusion of specific version numbers suggests a highly granular attack surface, where patching must be precise across many distinct build versions. This structure forces users into an active, high-friction management loop: monitoring notifications from multiple disparate sources for specific patch releases to restore systemic integrity. The implication is that maintaining security posture requires not just applying updates but managing complex dependency chains and version compatibility constraints. The underlying assumption driving this communication is the necessity of distributed vigilance; no single source can hold the complete picture, meaning cognitive sovereignty relies on the ability to synthesize these many scattered alerts into a unified action plan rather than reacting to singular crises.
Bridge questions: How can system administrators develop automated, cross-tool vulnerability reconciliation protocols to reduce the administrative burden of tracking these disparate updates? What structural changes are needed in software distribution practices to minimize version incompatibility risks across large developer toolsets? If external entities consistently release alerts targeting specific build exclusion lists, what is the most reliable internal metric for assessing the legitimacy and urgency of such notifications?
Sentinel — Human
The text reads like an excerpt from a formal security advisory, characterized by precise enumeration rather than narrative prose, leading to low synthetic suspicion.
