VDB
TNCVE-2026-20928
TNCVE-2026-20928
PUBLISHED
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
Timeline
- Apr 14, 2026 CVE Published
References
- Tenable: CVE-2026-20928 advisory