Vulnerability Advisory
The latest Vulnerability Advisory coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Now: Xbox Gaming Services CVE-2024-28916 Lets Low-Privilege Attackers Escalate to SYSTEM
A critical elevation-of-privilege vulnerability in Microsoft’s Xbox Gaming Services component, tracked as CVE-2024-28916, has been patched, but not before a public proof-of-concept demonstrated how...
Patch Now: Delta COMMGR Critical Vulnerabilities Allow Remote Code Execution via .isp Files
Delta Electronics has issued an urgent security advisory and released COMMGR version 2.10.0 to fix two high-severity vulnerabilities that could let attackers execute arbitrary code on industrial...
Rockwell's FactoryTalk Linx Flaw Scores 9.0: Deploy v6.50 Patch Now to Block Token Bypass
A critical vulnerability in Rockwell Automation’s FactoryTalk Linx allows attackers to bypass FTSP token validation and manipulate industrial communication drivers simply by flipping a Node.js...
Microsoft Issues Advisory for Critical Excel RCE Flaw CVE-2025-53739, Urges Immediate Patching
A newly discovered vulnerability in Microsoft Excel, tracked as CVE-2025-53739, could allow attackers to execute arbitrary code on victims' machines simply by convincing them to open a specially...
Microsoft Fixes Hyper-V Sync Bug (CVE-2025-47999) That Allows Adjacent Attackers to Crash Virtual Hosts
Microsoft has released a security update for a denial-of-service vulnerability in Windows Hyper‑V, cataloged as CVE‑2025‑47999, that lets an attacker on an adjacent network crash virtualisation...
Legacy Windows Telnet Zero-Click Flaw Grants Remote Admin Access via NTLM Bypass
Overview Microsoft’s Telnet Server, a legacy component rooted in the early days of Windows networking, is now the focus of serious cybersecurity concerns due to the discovery of a critical...
Critical Vulnerability in Rockwell PowerFlex 755 Drives Threatens Industrial Operations
The hum of industrial machinery is the heartbeat of modern civilization—from factory floors to power generation facilities—and at the core of these critical systems lie variable frequency drives...
Microsoft Patches Critical RCE Bug CVE-2025-21325 in Windows Server Core
Microsoft has released an urgent security update to address CVE-2025-21325, a critical vulnerability affecting multiple Windows Server Core installations. This remote code execution flaw, rated 9.8...
Critical Auth Bypass in My Security Account App—Patch v2.7.4 Now
A newly discovered vulnerability in the widely used My Security Account App poses significant risks to Windows administrators and enterprise security systems. This critical flaw, identified as...
GuardLogix CVE-2025-24478: Remote DoS Flaw Hits Rockwell 5580, 5380
A critical vulnerability in Rockwell Automation's GuardLogix safety controllers has security experts and industrial operators on high alert, with the Cybersecurity and Infrastructure Security Agency...
Patch now: Critical RCE flaws hit Schneider EcoStruxure IT products.
Schneider Electric Vulnerabilities: Urgent Advisory for EcoStruxure™ IT Users Schneider Electric has issued an urgent security advisory for users of its EcoStruxure™ IT products, warning of...
CVE-2024-49103: Critical WWAN Vulnerability in Windows Puts Systems at Risk
CVE-2024-49103: Critical WWAN Vulnerability in Windows Exposed A newly discovered vulnerability, tracked as CVE-2024-49103, has been identified in Windows' Wireless Wide Area Network (WWAN)...