SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-70290

MEDIUM · CVSS 5.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in the Windows Win32 Kernel Subsystem allows an authorized attacker to exploit uninitialized resources, potentially leading to local information disclosure. This could expose sensitive data to users with limited access privileges. Organizations using affected Windows systems should prioritize remediation to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-70290
Severity
MEDIUM
CVSS
5.5
EPSS
0.40%
Windows

Original NVD Description

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)