Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Unbound DNS Bug CVE-2026-42534 Slows Windows Networks, Patch Now
NLnet Labs disclosed CVE-2026-42534 on May 20, 2026, a medium-severity vulnerability in the Unbound DNS resolver that allows attackers to degrade DNS performance on Windows networks. The flaw,...
CVE-2026-41292: Unbound DNS Resolver Flawed by Malformed EDNS Options, Patch Now
A critical remote denial-of-service vulnerability in the widely used Unbound DNS resolver was disclosed on May 20, 2026, by NLnet Labs. Tracked as CVE-2026-41292, the flaw affects all Unbound...
Rsync Patched: Fix Critical Symlink Race in Daemon Mode for Windows Admins
A high-severity vulnerability in rsync, tracked as CVE-2026-29518, exposes daemons running without chroot protection to a symlink race condition. Disclosed on May 20, 2026, the flaw affects all rsync...
CVE-2026-45232: Rsync Proxy Bug Patched in 3.4.3, Low Severity but High Ops Risk
The rsync project has patched a freshly disclosed vulnerability, CVE-2026-45232, that lurks in the proxy handling logic of clients using the RSYNC_PROXY environment variable. Assigned a Low severity...
Fix Rsync Now: DNS Reverse Spoofing Bypasses Host Deny Rules in 3.4.2
On May 20, 2026, a medium-severity authorization bypass vulnerability, tracked as CVE-2026-43617, was disclosed for the widely-used rsync file synchronization tool. The flaw affects rsync daemon...
Microsoft MSRC Reveals Unbound CVE-2026-42923: NSEC3 Hash Attack Hits Windows DNS Resolvers
Microsoft’s Security Response Center has published details of CVE-2026-42923, a degradation-of-service vulnerability in NLnet Labs Unbound, the widely used open-source DNS recursive resolver....
Windows Admins: Patch Unbound Now for CVE-2026-42923 DNSSEC DoS
A medium-severity DNSSEC validation flaw tracked as CVE-2026-42923 was disclosed in May 2026, affecting NLnet Labs Unbound recursive DNS resolver up to version 1.25.0. The vulnerability allows a...
Critical Unbound DNSSEC Bug CVE-2026-33278: Upgrade to 1.25.1 Now
{ "title": "CVE-2026-33278 Unbound DNSSEC Flaw: Patch Unbound 1.25.1 Now", "content": "NLnet Labs on May 20, 2026, disclosed a critical vulnerability in its Unbound recursive DNS resolver that...
Unbound RPZ Vulnerability Crashes Windows DNS, Upgrade to 1.25.1 Now
A severe denial-of-service vulnerability in the Unbound recursive DNS resolver is putting Windows-based networks at risk of unplanned DNS outages. Tracked as CVE-2026-44608, the flaw affects NLnet...
Unbound DNSSEC bug crashes Windows DNS, patch now to stop outages
NLnet Labs has patched a critical denial-of-service vulnerability in the Unbound DNS resolver that allows a single malicious DNS response to crash the service, potentially knocking entire Windows...
Patch Unbound to 1.25.1 Now: DNS Poisoning Flaw CVE-2026-42960 Hits Windows
A high-severity DNS cache-poisoning vulnerability in NLnet Labs Unbound has been publicly disclosed, tracked as CVE-2026-42960, prompting urgent calls for system administrators to update to the...
CVE-2026-32792: Unbound DNSCrypt Flaw Lets Attackers Crash Windows DNS
A critical denial-of-service vulnerability in NLnet Labs Unbound DNS resolver, tracked as CVE-2026-32792, can crash the service when handling specially crafted DNSCrypt queries. Published on May 20,...