Intel has released the new microcode package 20260811, an update that includes security patches for eight different advisories and nine vulnerabilities, as well as fixing functional issues across various processor generations. The scope ranges from some 10th and 11th generation Core processors to Core Ultra, Panther Lake, and multiple Xeon families, including Xeon 6. Not all processors included in the package are affected by all vulnerabilities, and Intel has not yet announced any performance impact associated with these mitigations.
Key points of the Intel microcode 20260811 in 20 seconds
- Intel fixes nine CVEs spread across eight security advisories.
- The update covers models from 10th Gen Core up to Panther Lake and several Xeon families.
- Issues addressed include privilege escalation, information disclosure, and denial of service.
- 13th and 14th Gen Core processors also receive functional corrections.
- Intel recommends applying firmware updates distributed by motherboard or system manufacturers.
The package released on August 11 includes updates for Intel-SA-01379, Intel-SA-01404, Intel-SA-01423, Intel-SA-01428, Intel-SA-01435, Intel-SA-01441, Intel-SA-01442, and Intel-SA-01443. The official microcode repository also confirms functional changes for 10th Gen Core, 13th and 14th Gen Core, Core Ultra, Series 2 and 3, as well as various Xeon Scalable, Xeon D, and Xeon 6 processors.
An important detail is that the identifier microcode-20260811 does not represent a single universal fix for all processors. Intel groups different microcode revisions within the same package for various families, each with its own corrections and versions.
Xeon 6 hosts some of the most critical vulnerabilities
Among the included vulnerabilities, notable is INTEL-SA-01435, CVE-2026-20716, which has a CVSS score of 7.2 according to Intel’s published information. This issue relates to improper access control and could allow privilege escalation under certain Xeon 6 configurations.
This impacts recent enterprise products, including Xeon 6 with P-cores and various server and workstation variants.
Another significant fix involves INTEL-SA-01379, CVE-2025-31936, rated CVSS 7.0. This vulnerability concerns protected memory regions within System Management Mode (SMM) and certain environments using Intel Trust Domain Extensions (TDX).
TDX is Intel’s confidential computing technology designed to isolate virtual machines and protect their memory even from privileged system components. Therefore, any flaw in its isolation boundaries is especially important for cloud providers and multi-tenant data centers.
INTEL-SA-01404, associated with CVE-2025-31938, also affects TDX areas. Intel describes insufficient granularity in certain access controls, which might expose information across various recent Xeon families.
The official package confirms updates for platforms like Granite Rapids and Sierra Forest. For example, Xeon 6900/6700/6500 with P-cores move from 01000423 to 01000434, while Xeon 6900/6700 with E-cores update from 030003a3 to 030003b2.
Meteor Lake, Lunar Lake, Arrow Lake, and Panther Lake also receive updates
This update isn’t limited to servers.
INTEL-SA-01428, related to CVE-2025-35973, affects various client platforms and certain Xeon families. The vulnerability involves improper handling of values from privileged software like the kernel, hypervisor, or bare-metal environments, potentially allowing privilege escalation.
Affected families include Meteor Lake, Arrow Lake Mobile, Lunar Lake, and Panther Lake.
The microcode package reflects changes across all these platforms.
Meteor Lake progresses from revision 0x28 to 0x2a; Lunar Lake from 0x126 to 0x128; and several Panther Lake variants advance from 0x11b to 0x11c. Arrow Lake Series 2 also receives new versions depending on the specific model.
INTEL-SA-01441, related to CVE-2026-20760, similarly affects recent platforms such as Lunar Lake, Arrow Lake Mobile, and Panther Lake.
Intel categorizes the main impact as denial of service and privileged behavior under certain conditions. As with other firmware vulnerabilities, practical exploitation depends on prior access level and specific system configurations.
This is important because the processor list included in a microcode package might lead to the false conclusion that any system with those processors is equally vulnerable.
That is not the case.
Each advisory has its own affected product matrix.
Load Value Injection reappears in older processors
Older processors are also included in this update.
INTEL-SA-01423 addresses CVE-2026-20917, related to Load Value Injection techniques stemming from transient execution behavior.
Speculative execution allows CPUs to work ahead during uncertain conditions, enhancing performance but also underpinning many side-channel attack families identified since Spectre and Meltdown.
Here, incorrect forwarding of certain data during transient execution could lead to information exposure under specific circumstances.
Affected families include some Intel Core 10th and 11th Gen, 3rd Gen Xeon Scalable, Xeon D, and Xeon E-2300.
The 20260811 package updates, among others, the Mobile Ice Lake from 0xcc to 0xce, Rocket Lake from 0x65 to 0x66, Xeon Ice Lake Scalable from 0x0d000421 to 0x0d000433, and Xeon D-17xx/D-27xx from 0x010002f1 to 0x01000301.
INTEL-SA-01442 includes two CVEs
One of the eight advisories addresses two different vulnerabilities.
INTEL-SA-01442 includes CVE-2026-20713 and CVE-2026-20901, which are related to control flow issues and input validation problems within the firmware.
Both could lead to privilege escalation under certain conditions.
Affected products include recent generations of Xeon Scalable and various Xeon 6 series, as well as Xeon W families related to Sapphire Rapids.
This explains why the latest microcode updates Sapphire Rapids, Emerald Rapids, and the more recent generations simultaneously.
For example, Xeon Scalable 4th Gen moves from 2b000670 to 2b000685, while Emerald Rapids 5th Gen jumps from 210002e0 to 210002f4.
Finally, INTEL-SA-01443 fixes CVE-2026-20707, associated with a race condition that could cause denial of service in certain 3rd Gen Xeon Scalable and Xeon D processors.
13th and 14th Gen Core processors receive microcode, but not for these nine CVEs
One of the most potentially confusing aspects concerns Raptor Lake.
13th and 14th Gen Core processors move from microcode 0x133 to 0x137, but receiving a new revision within the 20260811 package does not mean they are affected by the nine vulnerabilities described earlier.
This distinction is especially important given stability problems that affected some desktop Raptor Lake chips and the subsequent microcode revisions issued by Intel.
The version 0x137 now replaces 0x133 in RPL-E/HX/S platforms included in the package.
There’s no indication in the release notes that this update addresses any of the nine CVEs from August.
New platforms: Bartlett Lake and Wildcat Lake appear as supported
The package also adds microcode support for platforms not previously included.
Intel identifies BTL-S12P and BTL-S816, corresponding to Series 2 P-core Core processors, with initial microcode 0x137.
Similarly, WCL, Wildcat Lake, is now included within the Series 3 Core Processors, with revision 0x0c.
These entries are listed under New Platforms, indicating that a prior revision has not been replaced in this package.
This highlights how Intel uses the same repository to distribute both security mitigations and support for new families and functional errata fixes.
BIOS and UEFI remain the primary update method
For end-user systems, servers, and workstations, the usual way to implement these updates is through a BIOS or UEFI update provided by the system, motherboard, or OEM manufacturer.
The manufacturer embeds the relevant microcodes into their firmware for compatible CPUs.
An advantage of this approach is that the processor gets updated early during boot, before the OS loads.
Linux users can also load microcode at startup using distribution packages. Intel maintains a dedicated repository, Intel-Linux-Processor-Microcode-Data-Files, to facilitate this process.
The August 11 release is the upstream source. However, system administrators should not assume that manual download and copying of files suffice for deployment.
In enterprise environments, it is best to use hardware manufacturer-supported mechanisms and Linux distribution tools, especially when validation and maintenance are required.
To verify the loaded microcode revision on a Linux system, you can run:
grep microcode /proc/cpuinfo | sort -uAnd you can check kernel messages with:
dmesg | grep -i microcodeThe correct version depends on the exact processor model. There is no single microcode version that applies universally to all systems.
No performance impact documented at this time
A common immediate question when new microcode is released is: how much performance is lost?
This concern has historical precedent.
Previous mitigations for speculative execution vulnerabilities have incurred measurable costs in certain scenarios—particularly workloads with frequent privilege mode switches, virtualization, or specific I/O operations.
In the notes for microcode-20260811, Intel does not document any performance loss associated with these fixes.
However, this does not mean the impact is guaranteed to be zero in every workload, only that it has not been officially recorded.
Until independent benchmarks and detailed technical analyses are available for each advisory, the correct stance is: there is currently no known or announced performance penalty by Intel for this package.
In data centers, especially those with TDX, intensive virtualization, or latency-sensitive workloads, it’s advisable to validate system behavior before mass deployment—without delaying essential security patches.
The 20260811 microcode demonstrates how security in modern CPUs is an ongoing process. The silicon itself remains unchanged, but certain behaviors can be modified over the processor’s lifetime through microcode updates.
For system administrators, the key takeaway is less about the CVEs and more about practical steps: review manufacturer firmware updates and verify whether specific models are affected before planning deployment.
Frequently Asked Questions
How many vulnerabilities does Intel microcode 20260811 fix?
The package includes security updates for eight advisories and nine CVEs, in addition to numerous functional corrections across various Core and Xeon generations.
Are 13th and 14th Gen Intel Core affected?
They receive the new microcode 0x137 compared to the previous 0x133, but Intel’s notes specify this as a functional update rather than a mitigation for the nine CVEs included in the eight security advisories.
How should the new microcode be installed?
The preferred method is updating the BIOS or UEFI provided by the system or motherboard manufacturer. Linux can also load microcode at startup through distribution packages.
Does the 20260811 microcode reduce performance?
Intel currently does not document any performance penalty for this package. Nonetheless, it’s advisable to await independent measurements, as impact may vary depending on workload.

