PatchSiren cyber security CVE debrief
CVE-2026-68873 Microsoft CVE debrief
CVE-2026-68873 is an insertion of sensitive information into log file vulnerability in the Windows Program Compatibility Assistant Service. This vulnerability allows an authorized attacker to disclose information locally. The CVSS score is 5.5, and the severity is MEDIUM. The vulnerability affects various versions of Windows 11 and Windows Server 2025. Defenders should prioritize reviewing and updating Windows Program Compatibility Assistant Service configurations to prevent local information disclosure. The CVE record and NVD vulnerability detail provide information on the vulnerability, including its description, CVSS score, and affected products.
- Vendor
- Microsoft
- Product
- Windows 11 version 23H2
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-17
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-17
Who should care
Defenders responsible for Windows systems, particularly those using Windows Program Compatibility Assistant Service, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-68873 is a medium-severity vulnerability that allows local information disclosure. Defenders should prioritize reviewing and updating Windows Program Compatibility Assistant Service configurations to prevent local information disclosure. The vulnerability affects various versions of Windows 11 and Windows Server 2025.
- Local information disclosure may lead to further exploitation
- Sensitive information may be exposed in log files
- Defenders need to verify affected versions and configurations
- Remediation requires updating Windows Program Compatibility Assistant Service configurations
Technical summary
The vulnerability is caused by the insertion of sensitive information into log files in the Windows Program Compatibility Assistant Service. This allows an authorized attacker to disclose information locally. The affected products include various versions of Windows 11 and Windows Server 2025.
Defensive priority
Defenders should prioritize reviewing and updating Windows Program Compatibility Assistant Service configurations to prevent local information disclosure.
Recommended defensive actions
- Review and update Windows Program Compatibility Assistant Service configurations to prevent local information disclosure
- Monitor system logs for sensitive information disclosure
- Implement compensating controls to limit local access to sensitive information
Evidence notes
The CVE record and NVD vulnerability detail provide information on the vulnerability, including its description, CVSS score, and affected products. The vulnerability is caused by the insertion of sensitive information into log files in the Windows Program Compatibility Assistant Service. This allows an authorized attacker to disclose information locally. The affected products include various versions of Windows 11 and Windows Server 2025. Defenders should verify affected versions and
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68873 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68873
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68873 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68873
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68873
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.