Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-48579 Exchange Online Info Disclosure: What Administrators Need to Know
Microsoft has officially listed CVE-2026-48579 as an information disclosure vulnerability affecting Microsoft Exchange Online, according to a recent entry in the Security Update Guide. The...
Microsoft Graph CVE-2026-47655: Why MSRC Confidence Ratings Matter for Cloud API Security
Microsoft’s publication of CVE-2026-47655 in its Security Update Guide marks a new information disclosure vulnerability in Microsoft Graph, the gateway to data across Microsoft 365 services. The...
CVE-2026-47644: Copilot Chat Information Disclosure Vulnerability Hits Microsoft Edge
A new information disclosure vulnerability tracked as CVE-2026-47644 has been publicly documented by the Microsoft Security Response Center (MSRC). The flaw, rated Important, resides in the Copilot...
Microsoft 365 Copilot Critical RCE Fixed Silently—Audit Custom Plugins Now
Microsoft dropped a security advisory on June 4, 2026 that left many admins breathing a sigh of relief—but also scratching their heads. CVE-2026-45497, a critical remote code execution (RCE)...
CVE-2026-42824: crafted prompts can leak M365 Copilot data, Microsoft warns
Microsoft has published CVE-2026-42824 in its Security Update Guide, flagging a new information disclosure vulnerability affecting the Microsoft 365 Copilot AI assistant. The disclosure underscores...
CVE-2026-48567: Azure HorizonDB Privilege Escalation—Immediate Steps for Azure Teams
CVE-2026-48567 is an elevation-of-privilege vulnerability in Azure HorizonDB, Microsoft’s preview PostgreSQL-compatible database service engineered for AI-era workloads. The disclosure, published...
CISA Warns Hitachi RTU500 Firmware Flaws Risk Critical OT Availability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has republished a security advisory from Hitachi Energy detailing critical firmware vulnerabilities in the RTU500 series remote...
CVE-2025-11482: CISA Reissues Advisory for Critical OPC-UA DoS Flaw in B&R PPT30 for Windows and OT Environments
CISA on June 4, 2026 republished ABB’s security advisory for CVE-2025-11482, underscoring the urgency of patching a high-severity denial-of-service (DoS) vulnerability that strikes at the heart of...
CISA Flags Critical libexpat Flaws in Hitachi ITT600 SA Explorer for IEC 61850 Simulation
On June 4, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) republished a high-priority advisory from Hitachi Energy, alerting industrial control system (ICS) operators and Windows...
CVE-2026-7310 Hitachi MACH HiDraw XML Patch Guide for OT Operators
Hitachi Energy’s MACH HiDraw software contains a locally exploitable heap-based buffer overflow that demands immediate attention from industrial control system (ICS) operators. Designated...
CISA Flags Critical Hard-Coded Credentials in NAVTOR NavBox Shipboard Systems—Urgent Patch Required
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a critical Industrial Control Systems (ICS) advisory on June 4, 2026, warning that the NAVTOR NavBox maritime data...
CVE-2026-41140: Critical Poetry Path Traversal Vulnerability Hits Windows – Upgrade Now
A supply-chain security flaw in the popular Python packaging tool Poetry has been flagged by Microsoft, carrying the identifier CVE-2026-41140. The vulnerability allows path traversal during the...