Live
GnuPG S/MIME Flaw CVE-2026-57062 Allows Attackers to Bypass Encryption Integrity with Short AES-GCM Tags·MSFT +2.1%Urgent CISA Alert: Unpatched Modbus TCP Flaws Expose Delta DVP12SE PLCs to Remote Attacks·NVDA +0.2%CISA Flags XZ Utils Flaw CVE-2025-31115 Endangering B&R Industrial Terminals, Urges Immediate Patching·GOOGL +1.7%CISA Issues Advisory for FUXA SCADA/HMI Authentication Bypass (CVE-2026-13207) Exposing User Roles·AMZN +1.1%CISA Warns: StoneFly Storage Concentrator Bugs Grant Root Access and Full Data Control·MSFT +2.1%Schneider Electric Patches Critical XXE Flaw in Data Center Expert – Update to 9.1.2 Now·NVDA +0.2%Mitsubishi MELSOFT Update Manager Flawed by 7-Zip Bugs, Industrial Systems Urged to Patch·GOOGL +1.7%CISA Flags 5 Critical File-Write Flaws in OFFIS DCMTK, Urging Immediate Medical Device Updates·AMZN +1.1%GnuPG S/MIME Flaw CVE-2026-57062 Allows Attackers to Bypass Encryption Integrity with Short AES-GCM Tags·MSFT +2.1%Urgent CISA Alert: Unpatched Modbus TCP Flaws Expose Delta DVP12SE PLCs to Remote Attacks·NVDA +0.2%CISA Flags XZ Utils Flaw CVE-2025-31115 Endangering B&R Industrial Terminals, Urges Immediate Patching·GOOGL +1.7%CISA Issues Advisory for FUXA SCADA/HMI Authentication Bypass (CVE-2026-13207) Exposing User Roles·AMZN +1.1%CISA Warns: StoneFly Storage Concentrator Bugs Grant Root Access and Full Data Control·MSFT +2.1%Schneider Electric Patches Critical XXE Flaw in Data Center Expert – Update to 9.1.2 Now·NVDA +0.2%Mitsubishi MELSOFT Update Manager Flawed by 7-Zip Bugs, Industrial Systems Urged to Patch·GOOGL +1.7%CISA Flags 5 Critical File-Write Flaws in OFFIS DCMTK, Urging Immediate Medical Device Updates·AMZN +1.1%

Security Alerts

The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 4:44 AM
Latest Most Read Breaking
Sort
Aes-gcm Cms · Cve-2026-57062

GnuPG S/MIME Flaw CVE-2026-57062 Allows Attackers to Bypass Encryption Integrity with Short AES-GCM Tags

A parsing quirk in GnuPG's S/MIME implementation can silently downgrade the authentication strength of encrypted messages, the GnuPG maintainers warned on June 28, 2026. The vulnerability, tracked as...

Advertisement
Cisa Advisory · Industrial Control Systems

CISA Warns: StoneFly Storage Concentrator Bugs Grant Root Access and Full Data Control

The U.S. Cybersecurity and Infrastructure Security Agency issued an urgent advisory on June 30, 2026, flagging multiple critical vulnerabilities in StoneFly Storage Concentrator appliances and...

SE Security Desk·3w ago
Cve-2026-8045 · Data Center Security

Schneider Electric Patches Critical XXE Flaw in Data Center Expert – Update to 9.1.2 Now

Schneider Electric has warned customers of a serious authenticated XML External Entity (XXE) injection vulnerability in its EcoStruxure IT Data Center Expert software, which if exploited could allow...

SE Security Desk·3w ago
7-zip Vulnerabilities · Ics Patching

Mitsubishi MELSOFT Update Manager Flawed by 7-Zip Bugs, Industrial Systems Urged to Patch

Mitsubishi Electric’s MELSOFT Update Manager, a utility deployed across thousands of industrial control system (ICS) engineering workstations, shipped with a dangerously outdated version of 7-Zip...

SE Security Desk·3w ago
Cisa Advisory · Dcmtk Security

CISA Flags 5 Critical File-Write Flaws in OFFIS DCMTK, Urging Immediate Medical Device Updates

A June 30, 2026 advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that five newly disclosed vulnerabilities in the OFFIS DCMTK toolkit could arm attackers with the...

SE Security Desk·3w ago
Cve-2026-9650 · Firmware Update

Schneider Electric Patches Credential-Stealing Vulnerability in EasyLogic T150, Saitel DP RTUs

Operators of energy grids, water utilities, and other critical infrastructure are urged to apply immediate firmware updates to Schneider Electric’s EasyLogic T150 and Saitel DP remote terminal...

SE Security Desk·3w ago
Cisa Kev · Oidc Authentication

CISA Urges Immediate Patching as SimpleHelp OIDC Auth Bypass Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-48558 to its Known Exploited Vulnerabilities (KEV) catalog, confirming that a critical authentication bypass...

SE Security Desk·4w ago
Cve-2026-58055 · Http Proxy Security

Critical Request Smuggling Flaw in nghttpx Proxy Enables HTTP Desync Attacks

A newly disclosed vulnerability in the nghttpx reverse proxy, tracked as CVE-2026-58055, allows attackers to smuggle malicious HTTP requests by exploiting a desynchronization between HTTP Upgrade and...

SE Security Desk·4w ago
Bpf Reuseport · Cve 2026 52910

Linux Kernel’s CVE-2026-52910 Patches Dangerous Race Condition in BPF Reuseport Cleanup

A newly published vulnerability tracked as CVE-2026-52910 has been patched in the Linux kernel, stamping out a race condition that could lead to use-after-free exploits in the classic Berkeley Packet...

SE Security Desk·4w ago