Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-34337 Windows Cloud Files Driver Bug Grants SYSTEM — Patch Now
Microsoft has listed a new elevation-of-privilege vulnerability under CVE-2026-34337 in its Security Update Guide, affecting the Windows Cloud Files Mini Filter Driver. The flaw, rated Important by...
Microsoft Patches High-Severity DWM Information Disclosure Flaw (CVE-2026-34336) in May 2026 Update
Microsoft closed out its May 12, 2026 security update cycle with a fix for CVE-2026-34336, a local information disclosure vulnerability in the Windows Desktop Window Manager (DWM) core library. The...
CVE-2026-34334 Windows TCP/IP Bug: Patch Now for SYSTEM Access
Microsoft has flagged CVE-2026-34334, a Windows TCP/IP privilege escalation vulnerability, with a critical exploitability assessment, pushing it to the top of the patch priority list for system...
Windows Server 2025 Gets Emergency Fix for Wormable NVMe-oF Kernel RCE in KB5087539
Microsoft’s May 2026 Patch Tuesday release includes a critical fix for CVE-2026-34332, a remote code execution vulnerability in the Windows kernel-mode driver for NVMe over Fabrics (NVMe-oF) on...
CVE-2026-33838: Windows MSMQ Bug Gives SYSTEM Access via Malformed Message
Microsoft disclosed a critical elevation-of-privilege vulnerability in its legacy Message Queuing service as part of the May 2026 Patch Tuesday releases. Tracked as CVE-2026-33838, the flaw allows a...
Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow
CVE-2026-33837 landed on the May 2026 Patch Tuesday with an Important severity rating. It’s a local elevation-of-privilege vulnerability inside tcpip.sys, the kernel-mode driver that handles the...
CVE-2026-33835: Microsoft Patches Windows Cloud Files Elevation of Privilege Flaw in May 2026 Patch Tuesday
Microsoft fixed an elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver as part of its May 2026 Patch Tuesday updates. The flaw, tracked as CVE-2026-33835, was disclosed...
CVE-2026-33833: Azure ML Notebook Spoofing Vulnerability Exposes Sensitive Data
Microsoft’s May 2026 Patch Tuesday release includes a fix for a newly disclosed vulnerability in Azure Machine Learning Notebooks that could allow attackers to access sensitive information through...
CVE-2026-33112: Critical SharePoint RCE Hits On-Prem Servers May 12
Microsoft dropped a bombshell on administrators this Patch Tuesday with the publication of CVE-2026-33112, a confirmed remote code execution vulnerability in Microsoft SharePoint Server. The...
CVE-2026-33110: Apply the SharePoint Server 2016 Security Update Regardless of Edition Label
Microsoft has released a critical security update to address CVE-2026-33110, a remote code execution vulnerability in SharePoint Server 2016. The patch is bundled under a knowledge base article that...
Patch CVE-2026-42899: ASP.NET Core DoS Bug Hits .NET 8/9/10
Microsoft disclosed CVE-2026-42899 on May 12, 2026, an Important-rated denial-of-service vulnerability in ASP.NET Core. The flaw stems from an infinite-loop condition that attackers can exploit to...
CVE-2026-42898: Emergency Patch for Dynamics 365 On-Prem RCE Flaw
Microsoft has published a new remote code execution (RCE) vulnerability, tracked as CVE-2026-42898, impacting on-premises deployments of Microsoft Dynamics 365. The advisory, released through the...