Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-45453 SharePoint Spoofing: Patch June Updates to Block Attacks
Microsoft has published CVE-2026-45453 in its Security Update Guide, marking a new spoofing vulnerability that on-premises SharePoint Server administrators will need to evaluate this June. The...
Hackers Weaponize Office Docs in CVE-2026-44824 RCE Attack — Patch Now
Microsoft has disclosed CVE-2026-44824, a critical remote code execution (RCE) vulnerability in Microsoft Office that has left some defenders puzzled by its CVSS 3.1 vector string:...
CVE-2026-44823: Critical Excel RCE Leaves Mac Office Users Waiting for Patch
Microsoft’s June 2026 Patch Tuesday brought a critical security advisory that Excel users on Mac cannot ignore—and cannot patch. The vulnerability, tracked as CVE-2026-44823, is a remote code...
CVE-2026-44821: Microsoft Office Info Leak Patched on Windows, Mac Users Must Wait
Microsoft's June 2026 Patch Tuesday brought a fix for CVE-2026-44821, an information disclosure vulnerability in Microsoft Office rated Important. The flaw, caused by an out-of-bounds read, could...
Microsoft Office CVE-2026-44819: Apply All Updates, Not Just Table List
Microsoft has issued an urgent and unusual advisory for CVE-2026-44819, a critical remote code execution (RCE) vulnerability in Microsoft Office, that forces organizations to rethink their patch...
Excel CVE-2026-44820 RCE Threat: Why CVSS Local Scoring Misleads Defenders
Microsoft has assigned CVE-2026-44820 as a Remote Code Execution (RCE) vulnerability in Microsoft Excel, yet the Common Vulnerability Scoring System (CVSS) v3.1 attack vector is listed as Local...
CVE-2026-44817 Excel RCE: Patch Now to Block Zero-Day Risk
Microsoft’s June 2026 Patch Tuesday brought an unwelcome shock for IT administrators worldwide: CVE-2026-44817, an Important-rated remote code execution (RCE) vulnerability in Microsoft Excel....
Microsoft delays critical Excel RCE patch for Mac Office—admins, act now
Microsoft has confirmed a critical remote code execution (RCE) vulnerability in Excel, tracked as CVE-2026-44818, but updates remain unavailable for Mac users running Office LTSC for Mac 2021, Office...
CVE-2026-42902 PowerToys: Patch Now for SYSTEM-Level Exploit Risk
Microsoft dropped CVE-2026-42902 into the June 2026 Patch Tuesday cycle on June 9, 2026, flagging an elevation-of-privilege vulnerability in Microsoft PowerToys. The advisory moves a utility adored...
CVE-2026-34335 AFD.sys: How Microsoft's Patch Confidence Aids Enterprise Prioritization
Microsoft has disclosed a new elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2026-34335, in its latest Security Update Guide. The...
Windows Device Health Attestation Flaw (CVE-2026-33828) Grants Attackers SYSTEM-Level Access
Microsoft’s June 2026 Patch Tuesday rollout on June 9 delivered a jolt to Windows administrators with the disclosure of CVE-2026-33828, a critical elevation-of-privilege vulnerability in the Device...
CVE-2026-40404: Critical Windows UDFS Elevation of Privilege Flaw Patched – What You Need to Know
Microsoft released a patch for CVE-2026-40404 on June 9, 2026, closing a high-severity elevation-of-privilege vulnerability in the Windows Universal Disk Format (UDFS) file system driver. The flaw...