Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
PinTheft LPE: CVE-2026-43494 Linux Kernel RDS Zero-Copy Double-Free Exploit Explained
A severe Linux kernel vulnerability tracked as CVE-2026-43494 was published through the National Vulnerability Database on May 21, 2026, exposing a double-free memory condition in the Reliable...
CVE-2026-43495: Out-of-Bounds Read in MediaTek T7xx Linux Modem Driver Exposes Kernel Memory
A newly published Linux kernel vulnerability, CVE-2026-43495, has been flagged by the National Vulnerability Database as of May 21, 2026. The flaw resides in the MediaTek T7xx 5G WWAN modem driver...
CVE-2026-43464: Linux Kernel Mellanox mlx5 XDP Multi-Buffer Bug Risks Availability for Windows Workloads
A newly disclosed Linux kernel vulnerability, designated CVE-2026-43464, exposes a subtle but dangerous flaw in the Mellanox mlx5 Ethernet driver that can crash the system or hang network...
Linux kernel panic bug CVE-2026-43496 lets CAP_NET_ADMIN users crash hosts via RED/QFQ tc misconfig
CVE-2026-43496 is a newly disclosed vulnerability in the Linux kernel’s networking stack that enables anyone with the ability to load a traffic control (tc) configuration to instantly crash the...
Linux IPv6 RPL Bug CVE-2026-43501 Hits WSL 2, Azure VMs
A newly disclosed out-of-bounds write vulnerability in the Linux kernel’s IPv6 implementation could hand attackers remote code execution or system crashes, and the blast radius stretches into...
Linux RDS Zerocopy Race Flaw CVE-2026-43502: Patch Linux VMs Now
On May 21, 2026, the National Vulnerability Database (NVD) published CVE-2026-43502, a newly disclosed flaw in the Linux kernel's Reliable Datagram Sockets (RDS) subsystem. The vulnerability, which...
CVE-2026-43497: Linux Kernel udlfb Driver Use-After-Free Vulnerability Poses Risk for USB Display Users
The Linux kernel’s udlfb driver, which enables framebuffer support for USB-connected DisplayLink-based devices, has been patched against a critical use-after-free flaw designated CVE-2026-43497....
Critical Linux Kernel mlx5e Driver Flaw (CVE-2026-43465) Exposes Systems to Attacks—What Windows Users Need to Know
A newly disclosed vulnerability in the Linux kernel’s mlx5e network driver, tracked as CVE-2026-43465, allows attackers to exploit improper accounting in the XDP multi-buffer implementation,...
WSL Users: Patch Critical Linux Kernel Flaw CVE-2026-43303 Now
The National Vulnerability Database (NVD) published details on CVE-2026-43303, a use-after-free vulnerability in the Linux kernel, on May 8, 2026. The flaw, rated high severity, stems from improper...
CVE-2026-0968: Low-Severity libssh SFTP Bug Exposes Windows Dependency Risks
A newly disclosed vulnerability in the libssh library’s SFTP client, cataloged as CVE-2026-0968, allows a malicious server to crash vulnerable applications. The flaw, rated low severity by...
CISA Adds Two RCE Flaws to KEV: Langflow CVE-2025-34291 and Trend Micro CVE-2026-34926
CISA updated its Known Exploited Vulnerabilities (KEV) catalog on May 21, 2026, adding two high-severity flaws that are under active attack. The vulnerabilities—CVE-2025-34291 in the Langflow...
CISA Warns: PixieFail Flaws Still Expose ABB B&R Industrial PCs
{ "title": "CISA Warns ABB B&R Industrial PCs: PixieFail UEFI Network Vulnerabilities (2026)", "content": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has sounded the...