The most important thing about CVE-2026-20715 isn't its CVSS 8.2 score—it's that the CVE itself is dated in the future. That temporal anomaly is a signal, not a typo, and it should change how you treat this vulnerability.
Future-dated CVEs are structurally unusual and historically correlate with disclosure events still in progress. When Intel has discovered compounding factors during extended testing, they've held CVE publication while revising scope. The combination of unusual dating, ambiguous scope language ('some firmware for some Intel AMT'), and an 8.2 score on a pure availability-only DoS suggests you're watching a disclosure unfold, not a finished characterization.
The CVSS scoring deserves scrutiny. An 8.2 for availability-only impact with no confidentiality or integrity involvement is atypical—CVSS rarely grants this threshold without compounding factors not visible in the current text. The transition from component-level 'high' to system-level 'none' availability suggests AMT's isolation architecture is containing the blast radius, which is informative but shouldn't comfort you. The real risk isn't this DoS propagating—it's every compromised AMT instance serving as hardware-privileged persistence infrastructure with documented paths to lateral movement.
Your priority: enumerate AMT instances across your environment. Not just currently-deployed systems—specifically identify hardware that may have been EOL'd while AMT remained silently enabled. That population represents permanent exposure debt: unpatchable, likely forgotten, still on the network. 'Some firmware' likely means the full scope is unknowable, which means assume broader exposure than confirmed. Treat availability-only AMT vulnerabilities with higher severity than their scores suggest—history shows these consistently expand in scope and severity post-disclosure.