SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-69288

MEDIUM · CVSS 5.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Windows GDI+ allows an authorized attacker to exploit uninitialized resources, potentially leading to local information disclosure. This could expose sensitive data to users with access to the affected system. Organizations using Windows should prioritize addressing this issue to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-69288
Severity
MEDIUM
CVSS
5.5
EPSS
0.31%
Windows

Original NVD Description

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.