Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-45653: Microsoft Patches Important Windows Kernel Elevation-of-Privilege Flaw in June 2026 Patch Tuesday
Microsoft’s June 9, 2026 security update addresses CVE-2026-45653, a Windows kernel elevation-of-privilege vulnerability that could allow an attacker to gain SYSTEM-level access on a compromised...
CVE-2026-45644: Live Share SDK Flaw Shows Why Patches Must Extend to Extensions
CVE-2026-45644, an elevation-of-privilege flaw in Microsoft's Live Share Canvas SDK, landed in the June 2026 Patch Tuesday bundle. The vulnerability, rated Important by Microsoft, allows an attacker...
CVE-2026-45608: Microsoft Patches Windows DHCP Client Information Disclosure Flaw – June 2026 Patch Tuesday
Microsoft's June 2026 Patch Tuesday release, published on June 9, contained a fix for CVE-2026-45608, an information disclosure vulnerability in the Windows DHCP Client service. The bug, listed in...
June 2026 Patch Tuesday: Fix This DWM Bug That Turns Low-Level Access Into SYSTEM Control
Microsoft’s June 9, 2026 Patch Tuesday rollout plugged CVE-2026-45637, an Important-rated elevation-of-privilege (EoP) vulnerability inside the Desktop Window Manager (DWM) core library. Assigned a...
Critical AFD.sys Flaw Grants SYSTEM Access—Patch CVE-2026-45603 Now
Microsoft has released a security update to address a critical elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2026-45603. The...
CVE-2026-45638: Windows WinSock AFD Driver Local Privilege Escalation Flaw Patched
Microsoft patched a critical local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) on June 9, 2026, as part of its monthly Patch Tuesday updates....
Patch Now: CVE-2026-45635 UPnP RCE Exploited in the Wild
Microsoft’s June 2026 Patch Tuesday delivered a critical fix for CVE-2026-45635, an Important-rated remote code execution (RCE) vulnerability in the Windows Universal Plug and Play (UPnP) Device...
DHCP Server CVE-2026-45602: Unauthenticated attackers can hijack network traffic with a CVSS 9.1 flaw in June 2026 Patch Tuesday.
Microsoft dropped a critical security patch on June 9, 2026, addressing a severe vulnerability in the Windows Dynamic Host Configuration Protocol (DHCP) Server. Tracked as CVE-2026-45602, this...
CVE-2026-11295: Google Low Rating vs 7.0+ CVSS — Patch Android WebView Now
Google has published details of CVE-2026-11295, a vulnerability in Chrome for Android's WebView component, disclosed on June 4, 2026. The flaw is patrolled in Chrome version 149.0.7827.53 and later,...
Incomplete NVD Enrichment for CVE-2026-11287 Leaves Chrome on Android Vulnerability in Limbo
The National Vulnerability Database enriched CVE-2026-11287 on June 8, 2026, adding a Common Platform Enumeration (CPE) entry that flags Google Chrome versions before 149.0.7827.53 on Android as...
CVE-2026-11263: Chrome on Android Flaw Sparks CPE Confusion – What You Need to Know
On June 4, 2026, the National Vulnerability Database published CVE-2026-11263, a low-severity flaw in Google Chrome’s WebAuthentication feature on Android. The vulnerability, fixed in Chrome...
Google Patches High-Severity CVE-2026-11226 in Chrome for Android — PreviewTab Same-Origin Bypass Allows Remote Attacks
A critical same-origin policy bypass has been patched in Google Chrome for Android, fixing a high-severity vulnerability that could let remote attackers access sensitive information across websites....