Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA Warns: XSS Flaw in Kieback & Peter DDC Controllers Risks HVAC Hijack
CISA published advisory ICSA-26-139-05 on May 19, 2026, warning that multiple Kieback & Peter DDC building controllers contain a cross-site scripting (XSS) vulnerability that allows...
CVE-2026-31702 F2FS Bug Threatens Windows WSL2 and Azure Linux VMs
A critical Linux kernel vulnerability, CVE-2026-31702, was published on May 1, 2026, exposing Windows environments running Linux workloads to potential privilege escalation and system compromise. The...
CVE-2026-31704: Critical ksmbd ACL Overflow Bites Linux Kernel—Patch Instantly
A nasty integer overflow in the ksmbd kernel SMB server, tracked as CVE-2026-31704, can hand attackers total system compromise via a specially crafted network packet. The bug, disclosed on May 2,...
Linux Kernel CVE-2026-31721 Exposes USB HID Gadget to Local Privilege Escalation — What Windows Users Need to Know
The Linux kernel project has issued a fix for a medium-severity vulnerability, tracked as CVE-2026-31721, that could allow a local attacker to corrupt kernel memory and potentially escalate...
Microsoft Patches ALDO Vulnerability CVE-2026-42822, Urges Immediate Update for Disconnected Azure Environments
Microsoft has addressed a security flaw in Azure Local Disconnected Operations (ALDO) tracked as CVE-2026-42822, issuing a fix that requires organizations running disconnected Azure environments to...
CVE-2026-42897: Critical Exchange OWA XSS Vulnerability Added to CISA KEV Catalog — Patch Now
CISA has escalated the urgency around a cross-site scripting (XSS) flaw in Microsoft Exchange Server’s Outlook Web Access (OWA) by adding CVE-2026-42897 to its Known Exploited Vulnerabilities (KEV)...
Cisco SD-WAN 0-Day Exploited: Patch Critical CVE-2026-20182 Now
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical authentication bypass flaw in Cisco’s Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV)...
Microsoft Authenticator Token Leak Lets Attackers Bypass MFA for Work Accounts
Microsoft has disclosed a serious information disclosure vulnerability in Microsoft Authenticator, assigned CVE-2026-41615, that could allow an attacker to steal sign-in access tokens for work...
Exchange Admins: Patch CVE-2026-42897 Spoofing Flaw in May 2026 Update
Microsoft’s May 2026 Patch Tuesday brought a critical disclosure for Exchange administrators: CVE-2026-42897, a spoofing vulnerability in Microsoft Exchange Server. This security flaw could allow...
Critical Session Hijacking Flaw in Siemens SIPROTEC 5 Relays Demands Immediate OT Action, CISA Warns
Operators of Siemens SIPROTEC 5 protection relays must urgently assess and patch their devices after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) amplified a alert about a serious...
Siemens CVE-2025-40833: Patch Now to Prevent OT Denial-of-Service Outages
On May 14, 2026, Siemens and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) jointly warned that a high-severity vulnerability, CVE-2025-40833, affects a broad spectrum of Siemens...
Siemens HMI Flaw CVE-2026-27662: Patch to V21 or Risk SYSTEM Takeover
Siemens, together with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), disclosed a high-severity vulnerability—tracked as CVE-2026-27662—on May 12–14, 2026, affecting its...