Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Chrome macOS Update Fixes WebUSB Code Execution Vulnerability (CVE-2026-13778)
Google has shipped a security patch for Chrome on macOS to close a critical use-after-free vulnerability in WebUSB that could let a local attacker run arbitrary code by connecting a malicious USB...
Chrome for iOS Gets Emergency Patch: Update to Version 150.0.7871.47 to Close Security Hole
Google has pushed out an urgent security patch for Chrome on iOS, bringing the browser to version 150.0.7871.47 to fix a dangerous flaw tracked as CVE-2026-13777. The update is now available through...
Update Chrome on Android Now to Patch Critical Sandbox Escape CVE-2026-14428
Google has patched a severe security hole in Chrome for Android that allows attackers to break out of the browser’s protective sandbox and potentially take full control of a device. Tracked as...
Two Joomla Extensions Under Active Attack: CISA Orders Agencies to Patch File-Upload Flaws
The U.S. Cybersecurity and Infrastructure Security Agency added two file-upload vulnerabilities in widely used Joomla extensions to its Known Exploited Vulnerabilities Catalog on March 26, 2025,...
Critical SNMP Vulnerability in Schneider Electric Easergy Relays Opens Door to Grid Disruption
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an advisory on July 9, 2026, alerting industrial operators to a critical remote-code-execution flaw in Schneider Electric's...
OpenPLC v3 Flagged End-of-Life as Critical File-Write Vulnerability Surfaces — Upgrade to v4 Now, CISA Urges
CISA just rang the death knell for OpenPLC v3. In a fresh advisory, the agency confirmed that CVE-2026-14480 — an unrestricted file upload flaw in the legacy platform — can be exploited to...
Schneider Electric Patches 7 Security Holes in PowerChute Serial Shutdown—Update Your UPS Software Now
Schneider Electric has released an emergency update for its PowerChute Serial Shutdown software, closing seven security vulnerabilities that expose Windows systems to potential takeover. The flaws,...
Windows Patch Alert: curl Flaw Leaks Old Proxy Credentials—Here’s the Fix
Windows users who depend on the ubiquitous curl command-line tool for proxy-authenticated web requests need to apply an urgent update. Microsoft’s security response center disclosed this week that...
Vulnerable Qualcomm Driver Could Crash Your Linux System – Here’s the Fix (CVE-2026-53339)
Linux kernel maintainers rushed a fix late last month for a bug that can bring down any system running a vulnerable Qualcomm SoC with a specific hardware misconfiguration. Tracked as CVE-2026-53339,...
Microsoft Flags Critical Linux RT Kernel Flaw CVE-2026-53327 That Could Freeze Systems
Microsoft has listed a new vulnerability—CVE-2026-53327—in its official Security Update Guide, shining a spotlight on a defect lurking deep within the Linux kernel’s debugging machinery. The...
CVE-2026-53332: Microsoft Flags Dangerous Qualcomm SLIMbus Driver Race Condition in Linux Kernel
Microsoft this week published a security advisory for a Linux kernel vulnerability—CVE-2026-53332—that could allow attackers to compromise devices during system startup. The flaw, a race...
Linux KVM Patch Resolves Spurious SEV-ES Warning When Windows VMs Shut Down
A newly assigned CVE has shed light on a subtle Linux kernel bug that could send Windows virtual machine administrators scrambling for false alarms. CVE-2026-53345, reserved for a KVM host-side...