Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-20928

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 35.9%
CVSS Severity
CVSS v3 Score 4.6
Products affected by CVE-2026-20928


Contact Us

Shodan ® - All rights reserved