ThreatCluster

Multiple Information Disclosure Vulnerabilities in Windows UPnP Device Host

First seen 8 Sep 2026, 19:20 UTC Api.Msrc.Microsoftcwe.mitre.orgwww.cve.org 40

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Microsoft disclosed two critical vulnerabilities in the Windows Universal Plug and Play (UPnP) Device Host, identified as CVE-2026-68830 and CVE-2026-69351. Both vulnerabilities allow authorized attackers to disclose sensitive information locally, specifically unauthorized access to the file system and file path information. The vulnerabilities stem from improper link resolution and privilege management issues. They affect all versions of Windows that support UPnP. Microsoft has released advisories detailing the vulnerabilities and their potential impact. No active exploitation has been reported as of the publication date. Organizations using affected systems are advised to monitor for updates and apply patches as they become available.

Key Points: • Two vulnerabilities (CVE-2026-68830 and CVE-2026-69351) disclosed on September 8, 2026. • Both allow unauthorized local information disclosure in Windows UPnP Device Host. • No active exploitation reported; organizations should prepare for patching.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-68830 published
Microsoft disclosed a vulnerability in Windows UPnP Device Host allowing information disclosure.
Api.Msrc.Microsoft
2026-09-08
CVE-2026-69351 published
Another vulnerability in Windows UPnP Device Host disclosed, also allowing information disclosure.
Api.Msrc.Microsoft