Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
ABB LVS MConfig CVE-2025-9970: Patch Now to Stop Credential Leaks
ABB has confirmed a high-severity credential-handling vulnerability, tracked as CVE-2025-9970, in its LVS MConfig software. The flaw affects versions 1.4.9.21 and earlier, leaving engineering...
CVE-2025-5517: Heap Overflow in ABB Terra AC EV Chargers Exposes Critical Infrastructure to Remote Attacks
A heap-based buffer overflow in ABB Terra AC wallbox chargers, tracked as CVE-2025-5517, could allow attackers to seize control of electric vehicle charging stations and pivot into connected...
Microsoft Patches CVE-2026-45498: Denial-of-Service in Defender Antimalware Platform 4.18
Microsoft has disclosed a denial-of-service vulnerability in its Microsoft Defender Antimalware Platform, tracked as CVE-2026-45498, as part of its May 2026 security update batch. The flaw affects...
Edge Admins: Patch Critical CVE-2026-45495 RCE Flaw Now
Microsoft released an urgent patch on May 15, 2026, for a high-severity remote code execution flaw in its Chromium-based Edge browser. The vulnerability, cataloged as CVE-2026-45495, enables...
CVE-2026-43414: Local Attackers Can Exploit Linux qla2xxx Bug for Kernel Takeover
The Linux kernel’s qla2xxx SCSI host bus adapter driver carries a critical memory‑management flaw that, when triggered, can free the same kernel object twice—a classic double‑free condition....
May 1 CVE: Linux MPTCP MSG_PEEK|MSG_WAITALL combo causes CPU soft lockup DoS
A newly published Linux kernel vulnerability, tracked as CVE-2026-43029, exposes a denial-of-service vector that can paralyze systems through an infinite spin in Multipath TCP (MPTCP) receive...
CVE-2026-5947: Critical BIND 9 SIG(0) Race Condition Flaw Demands Immediate Patching to Stop DNS Outages
ISC disclosed CVE-2026-5947 on May 20, 2026. A race condition in BIND 9's handling of SIG(0)-signed DNS traffic during query floods can crash the server. The high‑severity flaw demands immediate...
CVE-2026-5950: Unbounded Resend Loops in BIND 9 Recursive Resolver Demand Immediate Patching
The Internet Systems Consortium (ISC) has disclosed a medium-severity vulnerability in the BIND 9 recursive DNS resolver, tracked as CVE-2026-5950, that can force affected servers into a...
CVE-2026-5946: Urgent Patch for ISC BIND 9 DNS DoS Vulnerability – What Windows Administrators Must Know
The Internet Systems Consortium (ISC) has disclosed a high-severity denial-of-service flaw in BIND 9, tracked as CVE-2026-5946, that can crash the named DNS server with a single malicious packet....
Patch BIND 9 DoH Now: CVE-2026-3593 Allows Remote Code Execution
A high-severity vulnerability in BIND 9’s DNS-over-HTTPS (DoH) implementation demands immediate attention from DNS administrators. Disclosed on May 20, 2026, CVE-2026-3593 is a heap use-after-free...
CVE-2026-3039: BIND GSS-API TKEY Flaw Exposes Windows DNS to DoS Attacks
A critical remote denial-of-service vulnerability in ISC BIND 9, designated CVE-2026-3039, was publicly disclosed on May 20, 2026. The flaw permits unauthenticated attackers to exhaust a server’s...
CISA Mandates Urgent Patching for Drupal SQLi Bug Targeting PostgreSQL Sites
Federal cybersecurity agency CISA has added a critical Drupal Core SQL injection flaw, tracked as CVE-2026-9082, to its Known Exploited Vulnerabilities (KEV) catalog on May 22, 2026, after confirming...