How are you handling TPM firmware updates for vulnerabilities such as CVE-2026-6726 and CVE-2026-6727? In the past, updates sometimes required disabling BitLocker and Intel VT-x first. Do current systems still require those steps, or can the firmware be updated by temporarily suspending protection?
2 Answers
In our environment, Dell Command Update handles TPM firmware updates through the applicable BIOS or firmware package. It automatically takes care of suspending or disabling BitLocker as needed during the process.
The exact process depends on the TPM generation. Newer TPMs generally only require BitLocker to be suspended temporarily. Older TPMs may require fully decrypting the drive, applying the firmware update, and then encrypting it again. That can leave the machine less protected for a while, so keep it in a controlled location and monitor the process from start to finish.
That distinction is helpful. For older systems, the total time includes both decryption and re-encryption, so the device needs to remain physically secure throughout the maintenance window.

The re-enablement step hasn’t always been handled reliably, so we verify that BitLocker is active again after the update instead of assuming the tool restored it.