CVE-2026-25186
vulnerability analysis and mitigation

Overview

CVE-2026-25186 is an information disclosure vulnerability in the Windows Accessibility Infrastructure component (ATBroker.exe) that allows a low-privileged local attacker to expose sensitive information without user interaction. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday security update cycle, it affects a broad range of Windows client and server versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and resides in ATBroker.exe, the Assistive Technology Broker process that manages accessibility tools in Windows. An attacker with low-privilege local access can exploit this flaw to read sensitive data from the system without requiring elevated privileges or user interaction. The attack vector is local (AV:L), with low attack complexity and no scope change, meaning exploitation is confined to the affected system. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in a high confidentiality impact — a low-privileged local attacker can read and disclose sensitive data from the affected Windows system. There is no impact to system integrity or availability, and the vulnerability does not enable remote code execution or privilege escalation on its own. However, disclosed sensitive information could potentially be leveraged in a broader attack chain for lateral movement or credential theft (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released patches on March 10, 2026, addressing this vulnerability across all affected Windows versions. Administrators should update to the following minimum build versions: Windows 11 23H2 → 10.0.22631.6783, Windows 11 24H2 → 10.0.26100.7979, Windows 11 25H2 → 10.0.26200.7979, Windows 11 26H1 → 10.0.28000.1719, Windows 10 21H2 → 10.0.19044.7058, Windows 10 22H2 → 10.0.19045.7058, Windows 10 1607 → 10.0.14393.8957, Windows 10 1809 → 10.0.17763.8511, Windows Server 2016 → 10.0.14393.8957, Windows Server 2019 → 10.0.17763.8511, Windows Server 2022 → 10.0.20348.4830, Windows Server 2022 23H2 → 10.0.25398.2207, and Windows Server 2025 → 10.0.26100.32463. As a compensating control, organizations should restrict local user access and minimize the number of low-privilege accounts on sensitive systems. For systems that cannot be immediately patched, 0patch offers unofficial micropatches (Microsoft MSRC, 0patch Blog).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Sophos, Zero Day Initiative, and Lansweeper, though it did not receive individual spotlight coverage given its medium severity rating. 0patch released micropatches in May 2026 for CVE-2026-25186 alongside related Windows Accessibility Infrastructure vulnerabilities (CVE-2026-24291 and CVE-2026-25187), generating discussion on Reddit's r/SecOpsDaily and Bluesky infosec communities. The SANS Internet Storm Center also noted the vulnerability in its March 2026 Patch Tuesday diary (0patch Blog, Malware News, SANS ISC).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management