Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-4948: Local firewalld Flaw Gives Users Unauthorized Firewall Control – Patches Available
A newly disclosed vulnerability in firewalld, the popular Linux firewall management tool, allows unprivileged local users to modify runtime firewall rules without proper authorization. Tracked as...
CISA KEV June 2: Patch Linux cgroups & Android RCE by June 23
CISA added two high-severity vulnerabilities to its Known Exploited Vulnerabilities Catalog on June 2, 2026, including a Linux kernel privilege-escalation flaw dating back to 2022 and a newly...
Secure Tank Gauges Now: CISA Warns of Active Hacks Targeting Fuel Systems
A coalition of U.S. federal agencies has issued an urgent warning to operators of critical infrastructure: immediately secure automatic tank gauge (ATG) systems that are exposed to the internet. The...
CVE-2026-45494: How Microsoft Edge’s Split-Tab Feature Turned into a Spoofing Nightmare
Microsoft’s May 2026 Patch Tuesday brought a curious medium-severity vulnerability to light: CVE-2026-45494, an address bar spoofing bug in the Chromium-based Microsoft Edge browser. At first...
CISA Adds Oracle WebLogic RCE Flaw to KEV, Federal Patch Due June 2026
CISA has added a critical Oracle WebLogic Server vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, confirming active exploitation and setting a federal remediation deadline in June...
CVE-2026-33672 Patches Picomatch Vulnerability: Incorrect Glob Matching and Panics Fixed in Widely Used JavaScript Library
A new medium-severity vulnerability has been disclosed in Picomatch, the fast and widely used JavaScript glob-matching library. Tracked as CVE-2026-33672, the bug allows specially crafted glob...
Microsoft warns CVE-2026-28387 OpenSSL DANE bug forces full supply-chain patching across SQL Server and Windows OpenSSH.
Microsoft’s April 7, 2026 security advisory for CVE-2026-28387 pulls back the curtain on a gnarly use-after-free flaw lurking in OpenSSL’s DANE TLSA certificate validation. The bug, rated low...
CISA Flags Palo Alto GlobalProtect Auth Bypass CVE-2026-0257 as Actively Exploited: Patch by June 19
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability—tracked as CVE-2026-0257—to its...
CVE-2026-46121: Critical DAMON Kernel Bug Threatens WSL and Containers
The National Vulnerability Database assigned CVE-2026-46121 on May 28, 2026, flagging a critical use-after-free vulnerability in the Linux kernel's DAMON subsystem. The flaw resides in the sysfs...
Single-Line Linux Patch Fixes CVE-2026-46142 SR-IOV Hang, Warning for Windows Users
{ "title": "CVE-2026-46142 libwx SR-IOV VF Hang: Small Patch, Big Virtualization Lesson", "content": "The National Vulnerability Database published CVE-2026-46142 on May 28, 2026, a flaw that can...
CVE-2026-46113: Critical KVM Shadow Paging Bug Puts Windows VMs at Risk on Linux Hosts
A severe use-after-free vulnerability in the Linux kernel's Kernel-based Virtual Machine (KVM) has been assigned CVE-2026-46113, forcing organizations running Windows virtual machines on Linux hosts...
Linux USB Printer Bug CVE-2026-46167 Exposes Kernel Memory: Why Windows Users Should Care
A newly disclosed vulnerability in the Linux kernel's USB printer driver can leak sensitive kernel heap memory, raising alarms across the open-source ecosystem. Assigned CVE-2026-46167 on May 28,...