Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-64655: Critical Dynamics OmniChannel SDK Privilege Escalation Vulnerability
Microsoft has issued a critical security advisory for CVE-2025-64655, an elevation of privilege vulnerability affecting the Dynamics OmniChannel SDK storage containers that could allow attackers to...
CVE-2025-59245: Critical SharePoint Privilege Escalation Vulnerability Analysis
Microsoft has disclosed a critical elevation of privilege vulnerability in SharePoint Online, designated CVE-2025-59245, that requires immediate attention from organizations worldwide. This security...
CVE-2025-62207: Critical Azure Monitor Agent Privilege Escalation Vulnerability Patched
Microsoft has urgently addressed a critical elevation of privilege vulnerability in Azure Monitor Agent, designated CVE-2025-62207, that could allow attackers to gain elevated system privileges on...
CVE-2025-64656: Critical Azure Application Gateway Privilege Escalation Vulnerability
Microsoft has disclosed a critical elevation of privilege vulnerability in Azure Application Gateway, designated CVE-2025-64656, that could allow attackers to gain unauthorized administrative access...
CVE-2025-49752: Critical Azure Bastion Privilege Escalation Vulnerability
Microsoft has disclosed a critical elevation of privilege vulnerability in Azure Bastion, designated CVE-2025-49752, that could allow attackers to gain unauthorized administrative access to cloud...
Critical Opto22 EPIC RIO Flaw: groov Manage REST API Vulnerability Exposes Industrial Systems
A critical security vulnerability in Opto22's groov Manage REST API has been discovered, exposing industrial control systems to remote code execution attacks with root privileges. The flaw, tracked...
Festo MSE6 Hidden Functions Expose Critical OT Security Vulnerabilities (CVE-2023-3634)
Industrial control systems worldwide face new security threats as Festo's MSE6 energy-efficiency modules contain undocumented, remotely accessible functions that could enable attackers to compromise...
WebCTRL Open Redirect and XSS Vulnerabilities: Critical Security Alert
Automated Logic's WebCTRL building automation system has been confirmed vulnerable to serious security flaws that could allow attackers to redirect users to malicious websites and execute cross-site...
Emerson UPSMON PRO CVE-2024-3871: Critical RCE Vulnerability Analysis
A critical security vulnerability has been discovered in Emerson's Appleton UPSMON-PRO software that exposes industrial control systems to remote code execution attacks. Designated as CVE-2024-3871,...
CISA Issues Critical ICS Security Advisories for Schneider Electric and Yokogawa Systems
The Cybersecurity and Infrastructure Security Agency (CISA) has released a comprehensive package of six Industrial Control Systems (ICS) advisories, highlighting critical vulnerabilities in products...