CVE-2026-20928 | Microsoft Windows up to Server 2025 Recovery Environment improper removal of sensitive information before storage or transfer (WID-SEC-2026-1730)
A vulnerability categorized as problematic has been discovered in Microsoft Windows. The impacted element is an unknown function of the component Recovery Environment. Such manipulation leads to improper removal of sensitive information before storage or transfer.
This vulnerability is documented as CVE-2026-20928. The attack can be executed directly on the physical device. There is not any exploit available.
It is advisable to upgrade the affected component.