Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-21515: Azure IoT Central Elevation-of-Privilege Vulnerability—A Deeper Look at the Cloud Security Implications
Microsoft has officially acknowledged CVE-2026-21515, an elevation-of-privilege (EoP) vulnerability in Azure IoT Central, the company's fully managed IoT application platform. While the advisory is...
Power Apps CVE-2026-32172: Patch Now Before Exploit Details Leak
Microsoft has published CVE-2026-32172 as a Power Apps Remote Code Execution issue, but the public record is still thin on root-cause detail. In Microsoft’s Security Update Guide, the vulnerability...
CVE-2026-35431: Critical Entra Spoofing Flaw Needs Urgent Microsoft Fix
Microsoft has assigned CVE-2026-35431 to a spoofing vulnerability in Microsoft Entra ID Entitlement Management, but the public confidence signal attached to the entry is what makes this disclosure...
CVE-2026-26150: Microsoft Purview eDiscovery Elevation of Privilege Vulnerability Explained
Microsoft's latest Security Update Guide entry for CVE-2026-26150 is a reminder that cloud-era vulnerabilities are increasingly about privilege boundaries, not just code execution. The issue is...
CVE-2026-33819 Bing RCE: MSRC “Exploitation More Likely” Alerts Security Teams
Microsoft’s Security Update Guide entry for CVE-2026-33819 is the kind of disclosure that immediately puts defenders on alert, even before the full technical story is public. The issue is labeled a...
CVE-2026-33102: Microsoft 365 Copilot Elevation of Privilege Flaw Patched
Microsoft has quietly patched a security vulnerability in its Microsoft 365 Copilot service that could have allowed attackers to elevate their privileges within the AI-powered assistant. The flaw,...
CVE-2026-32210 Spoofing Bug in Dynamics 365: Verify Patch Now
Microsoft has disclosed a spoofing vulnerability in Dynamics 365 (online) that could allow attackers to impersonate legitimate business users or systems. Tracked as CVE-2026-32210, the flaw carries a...
CISA Warns of Active Exploitation in Critical Marimo RCE Vulnerability
CISA’s April 23, 2026 update to its Known Exploited Vulnerabilities Catalog is a reminder that the most dangerous security problems are often the ones attackers have already operationalized. This...
SpiceJet Booking Flaws Expose Passenger Data via PNR Enumeration (CVSS 7.5)
A newly disclosed vulnerability in the SpiceJet Online Booking System exposes passengers' personal information through two critical security flaws: PNR enumeration and a missing authentication check....
CISA Warns SpiceJet Booking Flaws Let Attackers Steal Passenger PNR Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding two security vulnerabilities in the SpiceJet Online Booking System. Tracked as CVE-2026-6375...
**CVE-2026-6074: Critical Path Traversal Threatens Intrado 911 Emergency Gateway**
A critical security flaw has been discovered in Intrado's 911 Emergency Gateway, a system used by public safety answering points (PSAPs) across the United States. The vulnerability, tracked as...
Intrado EGW CVE-2026-6074: Critical unauthenticated management, file access flaw
Intrado’s 911 Emergency Gateway (EGW) has landed in the crosshairs of a severe security advisory, and the details make clear why defenders in emergency services and enterprise telephony should...