Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA Warns: Unpatched KMW CCTV Flaw Lets Attackers Hijack Devices Remotely
A critical remote code execution vulnerability in KMW CCTV cameras hands attackers the keys to the entire device with zero authentication required, the U.S. Cybersecurity and Infrastructure Security...
CISA Warns: XCharge C6 EV Chargers Vulnerable to Full Takeover (CVSS 9.8)
The Cybersecurity and Infrastructure Security Agency (CISA) issued a stark warning on May 28, 2026, revealing that XCharge’s C6 electric vehicle charging stations harbor three critical...
CISA Warns: Stored XSS Bug in CP Plus NVRs Needs Urgent Patch and Network Isolation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an industrial control systems (ICS) advisory on May 28, 2026, for a stored cross-site scripting (XSS) vulnerability in CP Plus...
CISA Flags Critical Bluetooth Flaw in Frontier X2 Wearable That Can Spoof ECG and Health Readings
A critical Bluetooth authentication flaw in the Frontier X2 wearable and its companion mobile applications could let a nearby attacker spoof electrocardiogram (ECG) and other health readings, the...
CISA Warns: ABB Door Actuator Default Mode Lets Attackers Enter
CISA has republished an advisory from ABB regarding a critical vulnerability in the company’s Busch‑Welcome 2 Wire Door Opener Actuator. Designated CVE-2025-7705, the flaw permits physical...
CISA Flags Critical Hard-Coded Credentials Flaw in USR-W610 Industrial Converter
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on May 28, 2026, detailing a severe security vulnerability in the PUSR USR-W610 RS232/485 to Wi-Fi/Ethernet...
CISA republishes ABB's high-severity EIBPORT V3 KNX web flaw; patch firmware before 3.9.2 now.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has republished an advisory originally issued by ABB on October 7, 2025, warning that certain ABB EIBPORT KNX building automation...
WSL Teams Face Heavy Backport Work for Single-Line ext4 Kernel Fix
A newly disclosed Linux kernel vulnerability, CVE-2026-46094, exposes a critical flaw in the ext4 filesystem's extended attribute handling, allowing a four-byte memory read beyond valid buffer...
Linux Kernel KVM Patch Fixes Critical AMD Nested Virtualization Flaw
A newly published Linux kernel vulnerability, CVE-2026-46076, corrects a critical flaw in the Kernel-based Virtual Machine (KVM) hypervisor’s handling of nested virtualization on AMD processors....
Urgent Linux Kernel Flaw (CVE-2026-46026) in Qualcomm IPC Triggers Local DoS – What Windows Users Need to Know
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-46026, allows local users to crash systems that run Qualcomm’s Inter-Processor Communication (IPC) services. Published by...
CVE-2026-46082: KVM AMD SVM Vulnerability Fixed – What Windows Users Need to Know
A vulnerability in the Linux kernel's Kernel-based Virtual Machine (KVM) hypervisor that could have allowed malicious virtual machines to bypass AMD's virtualization protections has been patched. The...
Patch Now: Linux ALSA Loopback Driver Race Condition Allows Local Privilege Escalation
On May 27, 2026, the National Vulnerability Database published CVE-2026-46090, a significant security flaw in the Linux kernel’s ALSA snd-aloop driver. The vulnerability is a race condition that...