Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-8108: Fuji Tellus Kernel Driver Flaw Lets Local Users Hijack Windows OT Systems
A critical local privilege escalation bug in Fuji Electric Tellus 5.0.2 can hand any authenticated user full SYSTEM rights on industrial Windows machines. The vulnerability, tracked as CVE-2026-8108,...
ABB Automation Builder Gateway Vulnerability Exposes PLC Discovery on TCP Port 1217
CISA has republished ABB’s advisory for CVE-2024-41975, spotlighting a dangerous default configuration in the ABB Automation Builder Gateway for Windows. Before version 2.9.0, the software listens...
Patch ABB AC500 V3 PLCs Now: Remote Code Execution Flaws Fixed in Firmware 3.9.0
The ABB AC500 V3 programmable logic controller line has three critical security flaws that can be triggered remotely, according to advisories released by ABB on February 24, 2026, and re-published by...
ABB WebPro SNMP Flaws Allow Auth Bypass and DoS on UPS Systems
Three critical vulnerabilities in ABB’s WebPro SNMP Card for PowerValue UPS systems expose industrial control environments to authentication bypass and denial-of-service attacks. The flaws,...
CISA Warns of PowerSYSTEM Center Flaws in Energy Sector ICS
The Cybersecurity and Infrastructure Security Agency (CISA) released an industrial control systems (ICS) advisory on May 12, 2026, warning that multiple authenticated-user vulnerabilities affect...
ABB AC500 V3 CMS parser flaw CVE-2025-15467 allowed remote code execution before firmware 3.9.0 HF1.
A critical stack buffer overflow vulnerability in ABB’s AC500 V3 programmable logic controllers has been assigned CVE-2025-15467, prompting the vendor to release a hotfix firmware version 3.9.0...
CISA and G7 Release AI SBOM Minimum Elements for Supply Chain Security
The Cybersecurity and Infrastructure Security Agency (CISA) and G7 cybersecurity partners from Germany, Canada, France, Italy, Japan, the United Kingdom, and the European Union have jointly released...
CVE-2026-43500: High-Severity Linux Kernel Bug Puts Windows WSL Users at Risk of Local Privilege Escalation
A newly disclosed Linux kernel vulnerability tracked as CVE-2026-43500 is raising alarms across mixed Windows-Linux environments, particularly for organizations relying on Windows Subsystem for Linux...
CVE-2026-43298: Linux Kernel AMDGPU VCN 2.5 VF Teardown Flaw – What Windows Enthusiasts Need to Know
On May 8, 2026, the National Vulnerability Database published CVE-2026-43298, a flaw in the Linux kernel’s amdgpu driver that triggers a kernel warning during the teardown of virtual functions on...
CVE-2026-43299: Btrfs Kernel Crash Threatens Linux and Windows WSL Systems
A critical vulnerability in the Btrfs filesystem, tracked as CVE-2026-43299, can trigger a kernel crash when the filesystem transitions to read-only mode, potentially affecting millions of Linux...
Linux CVE-2026-43456 Exposes Windows WSL 2 & Azure VMs to Escalation Attacks
A type-confusion vulnerability in the Linux kernel’s network bonding driver, assigned CVE-2026-43456, was published by the National Vulnerability Database on May 8, 2026, and subsequently modified...
CVE-2026-43321: Linux BPF Verifier Register Liveness Bug Exposes Windows Systems via WSL and Azure
Microsoft published a security advisory for CVE-2026-43321 on May 8, 2026, flagging a high-severity flaw in the Linux kernel’s BPF verifier that allows local privilege escalation. The...