Live

Security Alerts

The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 6:41 PM
Latest Most Read Breaking
Sort
Cve-2026-45453 · Microsoft Security Update Guide

CVE-2026-45453 SharePoint Spoofing: Patch June Updates to Block Attacks

Microsoft has published CVE-2026-45453 in its Security Update Guide, marking a new spoofing vulnerability that on-premises SharePoint Server administrators will need to evaluate this June. The...

Advertisement
Cve-2026-44819 · Microsoft Office Security

Microsoft Office CVE-2026-44819: Apply All Updates, Not Just Table List

Microsoft has issued an urgent and unusual advisory for CVE-2026-44819, a critical remote code execution (RCE) vulnerability in Microsoft Office, that forces organizations to rethink their patch...

SE Security Desk·7w ago
Cve-2026-44820 · Cvss Av Local

Excel CVE-2026-44820 RCE Threat: Why CVSS Local Scoring Misleads Defenders

Microsoft has assigned CVE-2026-44820 as a Remote Code Execution (RCE) vulnerability in Microsoft Excel, yet the Common Vulnerability Scoring System (CVSS) v3.1 attack vector is listed as Local...

SE Security Desk·7w ago
Cve 2026-44817 · Microsoft Excel

CVE-2026-44817 Excel RCE: Patch Now to Block Zero-Day Risk

Microsoft’s June 2026 Patch Tuesday brought an unwelcome shock for IT administrators worldwide: CVE-2026-44817, an Important-rated remote code execution (RCE) vulnerability in Microsoft Excel....

SE Security Desk·7w ago
Cve-2026-44818 · Excel Remote Code Execution

Microsoft delays critical Excel RCE patch for Mac Office—admins, act now

Microsoft has confirmed a critical remote code execution (RCE) vulnerability in Excel, tracked as CVE-2026-44818, but updates remain unavailable for Mac users running Office LTSC for Mac 2021, Office...

SE Security Desk·7w ago
Cve-2026-42902 · It Patch Management

CVE-2026-42902 PowerToys: Patch Now for SYSTEM-Level Exploit Risk

Microsoft dropped CVE-2026-42902 into the June 2026 Patch Tuesday cycle on June 9, 2026, flagging an elevation-of-privilege vulnerability in Microsoft PowerToys. The advisory moves a utility adored...

SE Security Desk·7w ago
Afd.sys Vulnerability · Cve 2026-34335

CVE-2026-34335 AFD.sys: How Microsoft's Patch Confidence Aids Enterprise Prioritization

Microsoft has disclosed a new elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2026-34335, in its latest Security Update Guide. The...

SE Security Desk·7w ago
Cve-2026-33828 · Device Health Attestation

Windows Device Health Attestation Flaw (CVE-2026-33828) Grants Attackers SYSTEM-Level Access

Microsoft’s June 2026 Patch Tuesday rollout on June 9 delivered a jolt to Windows administrators with the disclosure of CVE-2026-33828, a critical elevation-of-privilege vulnerability in the Device...

SE Security Desk·7w ago
Cve-2026-40404 · Privilege Escalation

CVE-2026-40404: Critical Windows UDFS Elevation of Privilege Flaw Patched – What You Need to Know

Microsoft released a patch for CVE-2026-40404 on June 9, 2026, closing a high-severity elevation-of-privilege vulnerability in the Windows Universal Disk Format (UDFS) file system driver. The flaw...

SE Security Desk·7w ago