generated: '2026-08-30' method: searched source: https://www.amd.com/en/resources/product-security.html program: name: AMD Product Security Incident Response Team (PSIRT) published: true url: https://www.amd.com/en/resources/product-security.html contact_email: psirt@amd.com pgp_key: https://www.amd.com/en/resources/product-security/pgp-key.html support_policy: https://www.amd.com/en/resources/product-security/support-policy.html whitepaper: https://www.amd.com/system/files/documents/security-whitepaper.pdf bug_bounty: null bug_bounty_platform: null safe_harbor: null security_txt: served: false probed: - url: https://www.amd.com/.well-known/security.txt status: 404 - url: https://www.amd.com/security.txt status: 404 - url: https://developer.amd.com/.well-known/security.txt status: 404 - url: https://rocm.docs.amd.com/.well-known/security.txt status: 404 note: >- AMD runs a mature, publicly documented PSIRT with a dedicated mailbox and a published PGP key, but serves NO /.well-known/security.txt (RFC 9116) on any host. Every www.amd.com probe 302s to a branded 404 page. This is a one-file gap between a real disclosure program and a machine-discoverable one — the single cheapest fix available to AMD in this whole profile. advisories: published: true format: web page per bulletin, AMD-SB-#### identifiers index: https://www.amd.com/en/resources/product-security.html identifier_scheme: CVE identifier_authority: https://www.cve.org/ bulletin_url_pattern: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-.html classes: - Security Bulletin - Security Brief machine_readable: false machine_readable_note: >- The advisory index is HTML only. No CSAF, CVRF, OSV or VEX feed and no RSS/Atom feed was found; an agent must scrape the bulletin table. Each row does carry a dated publish/update pair and a CVE list, so the data is structured on the page even though no machine format is offered. recent_examples: - id: AMD-SB-4017 title: AMD Athlon, AMD Ryzen and AMD Ryzen Embedded Series Processor Vulnerabilities - May 2026 class: Security Bulletin published: '2026-05-12' - id: AMD-SB-3035 title: Quality-of-Service Feature Side Channels class: Security Brief published: '2026-05-12' - id: AMD-SB-7053 title: Floating Point Divider State Sampling on AMD CPUs class: Security Bulletin published: '2026-04-17' - id: AMD-SB-3023 title: AMD EPYC and AMD EPYC Embedded Series Processor Vulnerabilities - February 2026 class: Security Bulletin published: '2026-02-10' updated: '2026-04-14' evidence: - url: https://www.amd.com/en/resources/product-security.html status: 200 - url: https://www.amd.com/en/resources/product-security/pgp-key.html status: 200 - url: https://www.amd.com/en/resources/product-security/support-policy.html status: 200 - url: https://www.amd.com/.well-known/security.txt status: 404