Lyrie
Actively Exploited
CVSS 5.5ACTIVELY EXPLOITED4 sources verified·1 min read
By Lyrie Threat Intelligence·6/5/2026

MEDIUM: CVE-2021-27562 actively exploited — trustedfirmware trusted firmware-m

CVE: CVE-2021-27562

CVSS: 5.5 (3.1) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: MEDIUM

Status: ✅ Confirmed exploited in the wild (CISA KEV)

Affected

  • trustedfirmware trusted firmware-m

Summary

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

Verified Sources

References

  • https://developer.arm.com/support/arm-security-updates
  • https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/security_advisories/svc_caller_sp_fetching_vulnerability.rst
  • https://developer.arm.com/support/arm-security-updates
  • https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/security_advisories/svc_caller_sp_fetching_vulnerability.rst
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27562

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE
  4. [4]CISA KEV