CVE-2026-20928
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an una
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
MEDIUM · CVSS 4.6
EPSS 0.00171
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0