- What: Spectre vulnerabilities found on commercial RISC-V chips
- Impact: Potential for data leaks on widely used processors
Vulnerability Management Spectre vulnerabilities found on commercial RISC-V chips August 13, 2026 Share By SC Staff (Adobe Stock) Researchers have discovered that certain commercial RISC-V chips are susceptible to Spectre vulnerabilities, a family of security flaws related to speculative execution. These vulnerabilities, previously thought to primarily affect x86 and ARM architectures, can allow attackers to access sensitive data by exploiting how processors predict and execute instructions. This finding challenges the assumption that simpler chip architectures are immune to such sophisticated attacks, with further coverage provided by The Register. Academic researchers from the CISPA Helmholtz Center for Information Security and KU Leuven have demonstrated that commercially available out-of-order RISC-V processors, specifically the SiFive P550 and T-Head Xuantie C910/C920, are vulnerable to all major Spectre variants. These variants include Spectre-PHT, Spectre-BTB, Spectre-RSB, and Spectre-STL, which exploit different aspects of speculative execution, such as branch prediction and return stack buffers. Proof-of-concept attacks have successfully leaked arbitrary Linux kernel memory from the Xuantie C910 at a rate of 338 B/s. While software-based defenses exist for other architectures, they do not directly transfer to RISC-V due to the architecture's diversity and lack of introspection interfaces. The researchers emphasize that effective defense requires building new architectural primitives and ecosystem-wide tooling, as RISC-V inherits mature threat models without accumulated hardening. Responsible disclosure has led to some patches being merged into Linux, and vendors like SiFive and T-Head are addressing the findings. Source: The Register SC Staff Related Vulnerability Management Zoom vulnerabilities could enable RCE against meeting participants Laura French August 12, 2026 The flaws involving Zoom’s screenshare annotation feature were discovered with AI assistance. Vulnerability Management Cisco warns of 7 ClamAV flaws impacting Secure Endpoint Connector SC Staff August 12, 2026 The vulnerabilities, identified as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, impact ClamAV's parsers for various file formats. Vulnerability Management Microsoft SharePoint Server bug exploited in ransomware attacks Steve Zurier August 11, 2026 CISA gave no specifics, but one expert said it's potentially the work of China-linked Storm-2603. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds