Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Act Now: CVE-2026-40364 Word Zero-Click RCE via Preview Pane
Microsoft has confirmed a critical remote code execution flaw in Microsoft Word, tracked as CVE-2026-40364, that allows attackers to take over a system simply by having a user preview a malicious...
Critical Office RCE Bug: Patch CVE-2026-40363 Zero-Click Preview Flaw Now
Microsoft has released an emergency security update addressing CVE-2026-40363, a critical remote code execution (RCE) vulnerability in Microsoft Office that can be triggered through the Outlook...
CVE-2026-40360: Microsoft Excel Information Disclosure Vulnerability Patched – Enterprise Checklist for May 2026 Patch Tuesday
Microsoft’s May 2026 Patch Tuesday rollout includes a fix for CVE-2026-40360, an information disclosure vulnerability in Microsoft Excel that could allow remote attackers to read sensitive data...
CVE-2026-35440: Microsoft Word Information Disclosure Vulnerability Patched in May 2026 Patch Tuesday
Microsoft has officially published CVE-2026-35440, a newly disclosed information disclosure vulnerability affecting Microsoft Word. The advisory appeared in the Security Update Guide on May 12, 2026,...
May 12 Patch Fixes CVE-2026-35439: Authenticated SharePoint RCE via Deserialization
Microsoft has disclosed CVE-2026-35439, an Important-rated remote code execution vulnerability in on-premises SharePoint Server, patched in the May 12, 2026 security updates. The flaw stems from...
Microsoft Fixes Critical Windows Admin Center Flaw Allowing SYSTEM-Level Access
Microsoft has disclosed a critical elevation-of-privilege vulnerability in Windows Admin Center, tracked as CVE-2026-35438, that allows a low-privileged attacker to escalate to SYSTEM privileges by...
CVE-2026-35433 .NET Elevation of Privilege: What You Need to Know About the May 2026 Patch
Microsoft has officially disclosed a new elevation-of-privilege (EoP) vulnerability in the .NET framework, tracked as CVE-2026-35433, as part of its May 2026 Security Updates. The advisory, published...
Windows IKE Flaw Lets One Packet Crash VPN Servers—Patch Now
Microsoft's May 2026 Patch Tuesday release addresses a serious denial-of-service vulnerability in the Windows Internet Key Exchange (IKE) protocol, tracked as CVE-2026-35424. Disclosed on May 12,...
CVE-2026-35423: Windows 11 Telnet Client Information Disclosure – Patch Now or Remove Feature
{ "title": "CVE-2026-35423: Windows 11 Telnet Client Information Disclosure – Patch Now or Remove Feature", "content": "On May 12, 2026, Microsoft published CVE-2026-35423, an information...
CVE-2026-35422 TCP/IP Bypass: Microsoft Patches Critical Windows Vulnerability - Immediate Action Required
Microsoft has disclosed a serious security vulnerability in the Windows TCP/IP driver, tracked as CVE-2026-35422, that allows attackers to bypass critical security features. The flaw, revealed...
Microsoft’s May 2026 Patch: 67 Fixes, GDI RCE Gets Rare No-Panic Guidance
{ "title": "CVE-2026-35421: Windows GDI RCE—Patch Fast, Triage Calm, No Exploit Guesswork", "content": "Microsoft released its scheduled May 2026 security updates on Tuesday, addressing a total...
CVE-2026-35420 Under Active Attack: Patch Windows Kernel EoP Now
Microsoft's May 2026 Patch Tuesday cycle delivered a critical fix for CVE-2026-35420, a Windows Kernel elevation-of-privilege vulnerability with confirmed active exploitation. The flaw allows an...