CVE-2026-59130CWE-1303CWE-200information-disclosure

CVE-2026-59130

Medium · published August 11, 2026

CVSS v3.1
5.6
EPSS
0%
Percentile
26.4
In the wild
Unconfirmed
What it is

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

The record
Technical detail
CVSS v3.1
5.6 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00337 · 26.4th percentile
Weaknesses
CWE-1303 · Non-Transparent Sharing of Microarchitectural Resources; CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
Published
2026-08-11T21:18Z
Affected products (23)
ProductVersionsFixed in
microsoft/windows_10_1607< 10.0.14393.941810.0.14393.9418
microsoft/windows_10_1607< 10.0.14393.941810.0.14393.9418
microsoft/windows_10_1809< 10.0.17763.911510.0.17763.9115
microsoft/windows_10_1809< 10.0.17763.911510.0.17763.9115
microsoft/windows_10_21h2< 10.0.19044.766310.0.19044.7663
microsoft/windows_10_21h2< 10.0.19044.766310.0.19044.7663
microsoft/windows_10_21h2< 10.0.19044.766310.0.19044.7663
microsoft/windows_10_22h2< 10.0.19045.766310.0.19045.7663
microsoft/windows_10_22h2< 10.0.19045.766310.0.19045.7663
microsoft/windows_10_22h2< 10.0.19045.766310.0.19045.7663
microsoft/windows_11_23h2< 10.0.22631.751710.0.22631.7517
microsoft/windows_11_23h2< 10.0.22631.751710.0.22631.7517
microsoft/windows_11_24h2< 10.0.26100.910610.0.26100.9106
microsoft/windows_11_24h2< 10.0.26100.910610.0.26100.9106
microsoft/windows_11_25h2< 10.0.26200.910610.0.26200.9106
microsoft/windows_11_25h2< 10.0.26200.910610.0.26200.9106
microsoft/windows_11_26h1< 10.0.28000.270410.0.28000.2704
microsoft/windows_11_26h1< 10.0.28000.270410.0.28000.2704
microsoft/windows_server_2012all versions
microsoft/windows_server_2016< 10.0.14393.941810.0.14393.9418
microsoft/windows_server_2019< 10.0.17763.911510.0.17763.9115
microsoft/windows_server_2022< 10.0.20348.544010.0.20348.5440
microsoft/windows_server_2025< 10.0.26100.3322210.0.26100.33222
References (1)
EPSS history
Timeline
  • 11 AUG 17:03Z
    AMD Zen Information Disclosure Vulnerability
    cvelistv5