Live
CVE-2026-27456: Critical TOCTOU Race Condition in Linux mount Utility Explained·MSFT +0.1%CVE-2026-32225: Windows Shell Security Feature Bypass Vulnerability Analysis & Mitigation Guide·NVDA +3.0%Microsoft's 'Remote Code Execution' Terminology: Why CVSS AV:L Matters More Than Marketing Labels·GOOGL +1.2%CVE-2026-33095: Microsoft Office RCE Vulnerability with CVSS AV:L Vector Explained·AMZN +2.9%Excel Remote Code Execution Vulnerability Explained: Why CVSS AV:L Rating Doesn't Contradict Microsoft's Classification·MSFT +0.1%CVE-2026-32073: Critical AFD.sys Use-After-Free Vulnerability Enables Windows Privilege Escalation·NVDA +3.0%CVE-2026-32071: Microsoft's LSASS Denial-of-Service Vulnerability Requires Immediate Patching·GOOGL +1.2%CVE-2026-35611: Microsoft Warns of Critical ReDoS Vulnerability in Ruby's Addressable Gem·AMZN +2.9%CVE-2026-27456: Critical TOCTOU Race Condition in Linux mount Utility Explained·MSFT +0.1%CVE-2026-32225: Windows Shell Security Feature Bypass Vulnerability Analysis & Mitigation Guide·NVDA +3.0%Microsoft's 'Remote Code Execution' Terminology: Why CVSS AV:L Matters More Than Marketing Labels·GOOGL +1.2%CVE-2026-33095: Microsoft Office RCE Vulnerability with CVSS AV:L Vector Explained·AMZN +2.9%Excel Remote Code Execution Vulnerability Explained: Why CVSS AV:L Rating Doesn't Contradict Microsoft's Classification·MSFT +0.1%CVE-2026-32073: Critical AFD.sys Use-After-Free Vulnerability Enables Windows Privilege Escalation·NVDA +3.0%CVE-2026-32071: Microsoft's LSASS Denial-of-Service Vulnerability Requires Immediate Patching·GOOGL +1.2%CVE-2026-35611: Microsoft Warns of Critical ReDoS Vulnerability in Ruby's Addressable Gem·AMZN +2.9%

Articles from 2026

Browse all Windows news articles published in 2026

12 articles Page 376 of 1164
Articles from 2026
All archives
Cve 2026 27456 · Linux Security

CVE-2026-27456: Critical TOCTOU Race Condition in Linux mount Utility Explained

Microsoft's security advisory for CVE-2026-27456 reveals a critical Time-of-Check-Time-of-Use (TOCTOU) vulnerability in the util-linux mount utility that affects Linux systems, including those...

SE Security Desk·9w ago
Cve 2026 32225 · Msrc Advisory

CVE-2026-32225: Windows Shell Security Feature Bypass Vulnerability Analysis & Mitigation Guide

Microsoft's CVE-2026-32225 represents a critical Windows Shell security feature bypass vulnerability that demands immediate attention from system administrators and security teams. This advisory,...

SE Security Desk·9w ago
Attack Vector · Cve And Cvss

Microsoft's 'Remote Code Execution' Terminology: Why CVSS AV:L Matters More Than Marketing Labels

Microsoft's use of "remote code execution" in vulnerability descriptions doesn't always mean an attacker can trigger the exploit over a network connection. This discrepancy between marketing...

SE Security Desk·9w ago
Cve-2026-33095 · Cvss Av L

CVE-2026-33095: Microsoft Office RCE Vulnerability with CVSS AV:L Vector Explained

Microsoft's security advisory for CVE-2026-33095 describes a remote code execution vulnerability in Microsoft Office applications, yet the CVSS vector shows AV:L (Attack Vector: Local). This apparent...

SE Security Desk·9w ago
Cvss Scoring · Microsoft Excel Security

Excel Remote Code Execution Vulnerability Explained: Why CVSS AV:L Rating Doesn't Contradict Microsoft's Classification

Microsoft's recent security bulletin for Excel contains what appears to be a contradiction at first glance: a \"remote code execution\" vulnerability with a CVSS attack vector rating of AV:L, which...

SE Security Desk·9w ago
Afd.sys Use After Free · Cve-2026-32073

CVE-2026-32073: Critical AFD.sys Use-After-Free Vulnerability Enables Windows Privilege Escalation

Microsoft's CVE-2026-32073 represents a critical security vulnerability in the Windows Ancillary Function Driver (AFD.sys) that allows local attackers to escalate privileges on affected systems. This...

SE Security Desk·9w ago
Cve 2026 32071 · Identity Infrastructure

CVE-2026-32071: Microsoft's LSASS Denial-of-Service Vulnerability Requires Immediate Patching

Microsoft's security advisory for CVE-2026-32071 reveals a critical vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) that could allow attackers to cause...

SE Security Desk·9w ago
Addressable Templates · Cve 2026 35611

CVE-2026-35611: Microsoft Warns of Critical ReDoS Vulnerability in Ruby's Addressable Gem

Microsoft's security researchers have identified a critical Regular Expression Denial of Service (ReDoS) vulnerability in the Addressable Ruby gem, designated CVE-2026-35611. This flaw in a...

SE Security Desk·9w ago
Cve-2026-40385 · Exploitability Guidance

Defender Triage Targets Conditional CVE-2026-40385 Exploitation

Microsoft's security advisory for CVE-2026-40385 reveals a vulnerability with unusual exploitability characteristics that challenge conventional threat assessment models. The company explicitly...

SE Security Desk·9w ago
Heap-disclosure · Libpng Security

CVE-2026-34757: Critical libpng Use-After-Free Vulnerability Exposes Windows Systems to Heap Disclosure

Microsoft has confirmed a critical vulnerability in the libpng library that could allow attackers to access sensitive memory data from Windows systems. CVE-2026-34757, a use-after-free flaw in PNG...

SE Security Desk·9w ago
Certificate Revocation · Cve 2026 28388

CVE-2026-28388: How a Null Dereference in Delta CRL Processing Threatens Microsoft Entra Trust Chains

CVE-2026-28388 exposes a critical vulnerability in how Windows systems process Delta Certificate Revocation Lists, potentially disrupting authentication flows across Microsoft Entra ID and hybrid...

SE Security Desk·9w ago
Cve 2026 31789 · Heap Buffer Overflow

CVE-2026-31789: Critical Heap Buffer Overflow in Windows Hex Conversion Function

Microsoft has disclosed a critical heap buffer overflow vulnerability designated CVE-2026-31789 that affects multiple Windows versions through a flaw in hexadecimal conversion functions. This memory...

SE Security Desk·9w ago