Live
CVE-2025-10200: Chrome 140 Patches ServiceWorker Use-After-Free, Edge Users Must Update Immediately·MSFT +2.1%Siemens, Schneider, Daikin ICS Flaws Could Let Attackers Remotely Cripple Operations·NVDA +0.2%Vendor Won't Fix Daikin Gateway Pre-Auth Password Reset Bug—Public Exploit Code Heightens Risk for Energy Sector·GOOGL +1.7%Windows OT Security Alert: Siemens Flaw CVE-2025-40757 Leaks Device Databases Over BACnet·AMZN +1.1%Siemens SIMOTION Flaw: Unpatched NSIS Installer Bug Grants Attackers SYSTEM Access on Windows·MSFT +2.1%Critical Siemens SIVaaS Bug Exposes Windows-Hosted Automation VMs to Remote Tampering Without Logins·NVDA +0.2%SAP NetWeaver 10.0-Rated Exploits Eclipse Microsoft's Patch Tuesday as Enterprises Race to Patch·GOOGL +1.7%80 Fixes in September 2025 Patch Tuesday: SMB Audit Tool, NTFS RCE, and NTLM EoP Patched·AMZN +1.1%CVE-2025-10200: Chrome 140 Patches ServiceWorker Use-After-Free, Edge Users Must Update Immediately·MSFT +2.1%Siemens, Schneider, Daikin ICS Flaws Could Let Attackers Remotely Cripple Operations·NVDA +0.2%Vendor Won't Fix Daikin Gateway Pre-Auth Password Reset Bug—Public Exploit Code Heightens Risk for Energy Sector·GOOGL +1.7%Windows OT Security Alert: Siemens Flaw CVE-2025-40757 Leaks Device Databases Over BACnet·AMZN +1.1%Siemens SIMOTION Flaw: Unpatched NSIS Installer Bug Grants Attackers SYSTEM Access on Windows·MSFT +2.1%Critical Siemens SIVaaS Bug Exposes Windows-Hosted Automation VMs to Remote Tampering Without Logins·NVDA +0.2%SAP NetWeaver 10.0-Rated Exploits Eclipse Microsoft's Patch Tuesday as Enterprises Race to Patch·GOOGL +1.7%80 Fixes in September 2025 Patch Tuesday: SMB Audit Tool, NTFS RCE, and NTLM EoP Patched·AMZN +1.1%

Vulnerability

The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 9:46 PM
Latest Most Read Breaking
Sort
Browser Security · Browser Updates

CVE-2025-10200: Chrome 140 Patches ServiceWorker Use-After-Free, Edge Users Must Update Immediately

Google has shipped a critical patch for a use-after-free vulnerability in the ServiceWorker component of Chromium, tracked as CVE-2025-10200, with the release of Chrome version 140.0.7339.80/81 and...

Advertisement
Cisa · Createrestricteddirectory

Siemens SIMOTION Flaw: Unpatched NSIS Installer Bug Grants Attackers SYSTEM Access on Windows

Siemens and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have issued a coordinated advisory warning that several SIMOTION engineering tools contain a local privilege-escalation...

SE Security Desk·44w ago
Access Control · Cisa

Critical Siemens SIVaaS Bug Exposes Windows-Hosted Automation VMs to Remote Tampering Without Logins

A critical vulnerability in Siemens’ SIMATIC Virtualization as a Service (SIVaaS) has been assigned CVE-2025-40804, carrying a CVSS v3.1 base score of 9.1 and a CVSS v4 score of 9.3. The flaw—an...

SE Security Desk·44w ago
Cve-2023-27500 · Cve-2025-31324

SAP NetWeaver 10.0-Rated Exploits Eclipse Microsoft's Patch Tuesday as Enterprises Race to Patch

September’s Patch Tuesday delivered a predictable mix of Windows security updates and the usual Office headaches, but for enterprise security teams, the real fire alarm is ringing over SAP...

SE Security Desk·44w ago
Cve-2025-54916 · Cve-2025-54918

80 Fixes in September 2025 Patch Tuesday: SMB Audit Tool, NTFS RCE, and NTLM EoP Patched

Microsoft’s September 2025 Patch Tuesday landed with 80 security fixes, including a novel SMB hardening advisory that provides audit capabilities rather than a traditional vulnerability patch,...

SE Security Desk·44w ago
Asp.net · Cve-2024-21907

Microsoft Ships Fixed Newtonsoft.Json in SQL Server CU to Address High-Severity DoS Flaw CVE-2024-21907

Microsoft has confirmed that a high-severity vulnerability in Newtonsoft.Json, the ubiquitous JSON library for .NET, is being addressed through cumulative updates for SQL Server and other products....

SE Security Desk·45w ago
Cve-2025-55224 · Enterprise Security

CVE-2025-55224: Windows Win32K Race Condition Allows Hyper-V Escape and SYSTEM Access

A recently patched vulnerability in the Windows Win32K graphics subsystem allows an authenticated attacker—or a low-privileged process inside a Hyper-V virtual machine—to exploit a race condition...

SE Security Desk·45w ago
Cve-2025-54915 · Cybersecurity

Microsoft Patches Critical Type-Confusion Bug in Windows Defender Firewall Service (CVE-2025-54915)

Microsoft has released a patch for CVE-2025-54915, a local privilege escalation vulnerability in the Windows Defender Firewall Service that exploits a type-confusion error. The flaw, described by...

SE Security Desk·45w ago
Bitlocker · Boot Security

Microsoft Fixes High-Impact BitLocker Use-After-Free Vulnerability (CVE-2025-54911)

Microsoft has disclosed a high-severity use-after-free vulnerability in Windows BitLocker, tracked as CVE-2025-54911, that could allow a local attacker to elevate privileges from a standard user...

SE Security Desk·45w ago