Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Exchange Spoofing Flaw CVE-2026-45501: Patch Now to Block Phishing Attacks
Microsoft's June 2026 Patch Tuesday rollout includes a crucial fix for an Important-rated spoofing vulnerability in on-premises Exchange Server. Tracked as CVE-2026-45501, this security flaw could...
Windows UPnP Device Host RCE (CVE-2026-45599) Patched in June 2026 Update
Microsoft has pushed out a security update for a high-severity remote code execution vulnerability in the Windows UPnP Device Host service. Tracked as CVE-2026-45599, the flaw carries an 8.1 CVSS...
Deploy June 9 Patch for CVE-2026-45500 Exchange Spoofing Risk
Microsoft’s June 2026 Patch Tuesday rollout on June 9 delivered a crucial security fix for Microsoft Exchange Server administrators. Among the updates is CVE-2026-45500, a spoofing vulnerability...
Patch Tuesday Fix: CVE-2026-45597 Gives SYSTEM Access via UI Automation Bug
Microsoft's June 9, 2026 security update addresses a significant local elevation-of-privilege vulnerability tracked as CVE-2026-45597. The flaw resides in the Windows UI Automation Manager,...
Chrome Android WebView Bug CVE-2026-11178 Leaks Cross-Origin Data, Patch Now
Google has patched a medium-severity security flaw in Chrome for Android that could allow malicious websites to bypass WebView policies and potentially leak sensitive cross-origin data. The...
June 2026 Patch Tuesday: Windows MotW Bypass CVE-2026-45595 Gets Fix
Microsoft has released a security update to address CVE-2026-45595, a Windows Mark of the Web (MotW) security feature bypass vulnerability, as part of the June 9, 2026 Patch Tuesday. The flaw, rated...
CVE-2026-45604: Microsoft Patches Windows Managed Installer Information Disclosure Bug
Microsoft rolled out its June 2026 Patch Tuesday updates, addressing 49 vulnerabilities across the Windows ecosystem. Among them, CVE-2026-45604 stands out for its targeted impact on the Managed...
Google Patches Chrome Android Autofill Bug That Bypasses Same-Origin Security
Google has patched a low-severity security flaw in Chrome for Android that gave remote attackers a way to bypass same-origin protections through the browser’s Autofill system. Tracked as...
Chrome for Android Patch 149.0.7827.53 Fixes High-Severity UI Spoofing Bug CVE-2026-10984
Google has patched a high-severity vulnerability in Chrome for Android that could allow a remote attacker to spoof user-interface elements, potentially tricking users into revealing sensitive...
Patch Windows AppID flaw now: CVE-2026-45594 leaks sensitive memory
Microsoft disclosed CVE-2026-45594 on June 9, 2026, as part of its monthly Patch Tuesday release, an Important-rated information disclosure vulnerability in the Windows Application Identity (AppID)...
CVE-2026-45593: Windows SDK Privilege Escalation Forces Urgent Patching for Developer Environments
On June 9, 2026, Microsoft’s monthly security release included an unusual entry: CVE-2026-45593, an elevation-of-privilege vulnerability in the Windows Software Development Kit (SDK). The fix...
Patch now: Critical WinINet EoP bug CVE-2026-45592 gives attackers SYSTEM access.
Microsoft's June 2026 Patch Tuesday, released on June 9, brings a critical fix for CVE-2026-45592, an elevation-of-privilege vulnerability in the Windows Internet (WinINet) API library. The flaw,...