Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-7790: Critical DoS Flaw in Erlang Cowlib Chunked HTTP Parser – Upgrade to 2.16.1 Now
A high-severity denial-of-service vulnerability tracked as CVE-2026-7790 has been disclosed in cowlib, the low-level HTTP parsing library that underpins the popular Cowboy web server for Erlang/OTP....
CVE-2026-33814 HTTP/2 Bug in Go: Patch Now to Prevent Client DoS
A single malicious SETTINGS frame can bring Go-based clients to a grinding halt, forcing applications into an infinite processing loop that consumes CPU resources until manual intervention. Security...
CPython CR/LF injection bug in HTTP proxy tunnel threatens Windows users
A medium-severity vulnerability in CPython’s HTTP proxy tunneling code leaves Windows users open to CR/LF injection attacks, according to an advisory published in April 2026. Tracked as...
CVE-2026-45659: Patch All SharePoint 2016 Editions, Not Just Enterprise Server
Microsoft’s May 2026 Patch Tuesday brought a critical remote code execution vulnerability, CVE-2026-45659, to light—and with it, a labeling quirk that could trip up SharePoint administrators. The...
CVE-2026-48172 Under Active Attack: CISA Orders cPanel/LiteSpeed Patch by June 16
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical LiteSpeed cPanel plugin privilege-escalation flaw, tracked as CVE-2026-48172, to its Known Exploited Vulnerabilities...
Update Microsoft Defender to 1.1.26040.8 to Fix CVE-2026-45584 RCE Flaw
Microsoft dropped a critical security update on May 19, 2026, for the Microsoft Malware Protection Engine—the silent workhorse behind Windows Defender and several other Microsoft security products....
ABB B&R Controller Flaw Lets Unauthenticated Attackers Crash Critical Systems
CISA has republished an advisory from ABB on May 26, 2026, shining a spotlight on CVE-2025-3450—a vulnerability that allows an unauthenticated network attacker to trigger denial-of-service...
Microsoft Patches CVE-2026-41091: Defender Engine EoP Fixed in v1.1.26040.8
Microsoft patched a high-severity elevation-of-privilege vulnerability in its Malware Protection Engine on May 20, 2026. The flaw, tracked as CVE-2026-41091, could allow an attacker to gain...
CISA Warns ABB AC500 V2 PLC Flaw Leaks Data via Modbus TCP
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has amplified a critical advisory for industrial control systems, republishing ABB’s security notice for CVE-2025-7745 on May 26,...
CVE-2025-8754: ABB zenon Remote Transport Service Allows Unauthenticated Remote Reboot
ABB's widely deployed zenon industrial automation platform contains a severe vulnerability, tracked as CVE-2025-8754, that allows unauthenticated attackers to remotely reboot affected systems. The...
CISA Flags Critical Hard-Coded VNC Password in Eppendorf BioFlo 320 Bioreactor
A medical device used in pharmaceutical and biotech production carries a vulnerability so basic it could let attackers waltz into critical systems. The Cybersecurity and Infrastructure Security...
Critical VLC Vulnerabilities Force ABB to Issue Emergency Patch for Industrial Camera Software
ABB has released an urgent security update for its Ability Camera Connect software after discovering that a set of high-severity vulnerabilities in the embedded VLC media player component could allow...