Security Advisory

CVE-2026-20928

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-14 16:57:51
Last updated 2026-05-12 17:38:47
Assigner microsoft
State PUBLISHED

Description

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.