Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-11029: Critical Chrome Android Drag-and-Drop Vulnerability Allows Sandbox Escape
Google has patched a high-severity security flaw in Chrome for Android that could have allowed attackers to escape the browser's sandbox through a deceptive drag-and-drop interaction. Tracked as...
Chrome for Android CVE-2026-11012: CPE Scanner Blind Spots Expose Fleets
Google Chrome’s June 4, 2026, security bulletin dropped a critical fix for Android users: CVE-2026-11012, a use-after-free vulnerability in the Serial component, patched in version 149.0.7827.53...
CVE-2026-45600: Microsoft Patches Important Windows Kernel Privilege Escalation Flaw in June 2026 Patch Tuesday
Microsoft’s June 2026 security update, released on the 9th as part of its regular Patch Tuesday cycle, addresses a local privilege escalation vulnerability tracked as CVE-2026-45600. The flaw,...
CVE-2026-47631 Exchange Spoofing: Act Now Despite Sparse Patch Details
Microsoft dropped CVE-2026-47631 into its Security Update Guide this week, flagging a spoofing vulnerability in Microsoft Exchange Server. The advisory offers almost nothing beyond a high-confidence...
Patch CVE-2026-45596 now: Windows AFD bug grants SYSTEM access to all users
Microsoft kicked off its June 2026 Patch Tuesday with a critical fix for CVE-2026-45596, a local elevation of privilege vulnerability lurking in the Windows Ancillary Function Driver for WinSock,...
Apply Microsoft’s Emergency Exchange Patch Now to Block CVE-2026-45583 Attacks
Microsoft Exchange administrators face yet another critical patching fire drill with the release of CVE-2026-45583, a remote code execution vulnerability that puts on-premises mail servers at...
CVE-2026-45636: Patch Windows NTFS VHD Flaw Now Despite Misleading "Remote" Label
Microsoft dropped its June 2026 Patch Tuesday update, and among the fixes is CVE-2026-45636, a vulnerability that underscores why security classifications can be misleading. The flaw, rated...
CVE-2026-45504: Apply June Exchange Patch Now to Block Privilege Escalation
Microsoft disclosed CVE-2026-45504—an elevation-of-privilege vulnerability in Microsoft Exchange Server—as part of its June 9, 2026 Patch Tuesday release. The vulnerability carries an Important...
CVE-2026-45503 Exchange Info Disclosure: Patch Immediately to Protect Sensitive Data
Microsoft has published a critical security advisory for CVE-2026-45503, an information disclosure vulnerability affecting on-premises Exchange Server deployments. The advisory, available through the...
Patch Now: Critical CVE-2026-45598 AFD.sys Bug Gives Hackers SYSTEM Access
Microsoft's June 2026 Patch Tuesday has arrived with a crucial fix for CVE-2026-45598, an Important-rated elevation-of-privilege vulnerability residing in the Windows Ancillary Function Driver for...
CVE-2026-45502: Why Microsoft's 'Confirmed' Report Confidence Raises the Stakes for Exchange Server Admins
Microsoft published CVE-2026-45502 on June 9, 2026, marking it as a critical information disclosure vulnerability in Microsoft Exchange Server. The advisory, posted in the Microsoft Security Response...
Microsoft Urges Patching of CVE-2026-45601: WinSock AFD Driver Exploit Leads to SYSTEM Access
Microsoft’s June 2026 Patch Tuesday closed a dangerous elevation-of-privilege hole in the Windows Ancillary Function Driver for WinSock (AFD). Tracked as CVE-2026-45601, the flaw grants a locally...