Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
GnuPG S/MIME Flaw CVE-2026-57062 Allows Attackers to Bypass Encryption Integrity with Short AES-GCM Tags
A parsing quirk in GnuPG's S/MIME implementation can silently downgrade the authentication strength of encrypted messages, the GnuPG maintainers warned on June 28, 2026. The vulnerability, tracked as...
Urgent CISA Alert: Unpatched Modbus TCP Flaws Expose Delta DVP12SE PLCs to Remote Attacks
Federal cybersecurity authorities issued an urgent warning on June 30, 2026, regarding two critical vulnerabilities in Delta Electronics DVP12SE programmable logic controllers (PLCs) that allow...
CISA Flags XZ Utils Flaw CVE-2025-31115 Endangering B&R Industrial Terminals, Urges Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has republished an ABB PSIRT advisory warning that CVE-2025-31115, a high-severity vulnerability in the XZ Utils data compression...
CISA Issues Advisory for FUXA SCADA/HMI Authentication Bypass (CVE-2026-13207) Exposing User Roles
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an urgent industrial control systems (ICS) advisory on June 30, 2026, for a dangerous authentication bypass vulnerability in...
CISA Warns: StoneFly Storage Concentrator Bugs Grant Root Access and Full Data Control
The U.S. Cybersecurity and Infrastructure Security Agency issued an urgent advisory on June 30, 2026, flagging multiple critical vulnerabilities in StoneFly Storage Concentrator appliances and...
Schneider Electric Patches Critical XXE Flaw in Data Center Expert – Update to 9.1.2 Now
Schneider Electric has warned customers of a serious authenticated XML External Entity (XXE) injection vulnerability in its EcoStruxure IT Data Center Expert software, which if exploited could allow...
Mitsubishi MELSOFT Update Manager Flawed by 7-Zip Bugs, Industrial Systems Urged to Patch
Mitsubishi Electric’s MELSOFT Update Manager, a utility deployed across thousands of industrial control system (ICS) engineering workstations, shipped with a dangerously outdated version of 7-Zip...
CISA Flags 5 Critical File-Write Flaws in OFFIS DCMTK, Urging Immediate Medical Device Updates
A June 30, 2026 advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that five newly disclosed vulnerabilities in the OFFIS DCMTK toolkit could arm attackers with the...
Schneider Electric Patches Credential-Stealing Vulnerability in EasyLogic T150, Saitel DP RTUs
Operators of energy grids, water utilities, and other critical infrastructure are urged to apply immediate firmware updates to Schneider Electric’s EasyLogic T150 and Saitel DP remote terminal...
CISA Urges Immediate Patching as SimpleHelp OIDC Auth Bypass Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-48558 to its Known Exploited Vulnerabilities (KEV) catalog, confirming that a critical authentication bypass...
Critical Request Smuggling Flaw in nghttpx Proxy Enables HTTP Desync Attacks
A newly disclosed vulnerability in the nghttpx reverse proxy, tracked as CVE-2026-58055, allows attackers to smuggle malicious HTTP requests by exploiting a desynchronization between HTTP Upgrade and...
Linux Kernel’s CVE-2026-52910 Patches Dangerous Race Condition in BPF Reuseport Cleanup
A newly published vulnerability tracked as CVE-2026-52910 has been patched in the Linux kernel, stamping out a race condition that could lead to use-after-free exploits in the classic Berkeley Packet...