SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-69351

MEDIUM · CVSS 5.5 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Windows Universal Plug and Play (UPnP) Device Host is vulnerable to unauthorized information disclosure, allowing an attacker with local access to expose private personal information. Organizations using affected Windows systems should prioritize addressing this vulnerability to mitigate potential data breaches. Users with sensitive data or those in regulated industries are particularly at risk and should take immediate action.

CVE
CVE-2026-69351
Severity
MEDIUM
CVSS
5.5
EPSS
0.47%
Windows

Original NVD Description

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.