Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Tuesday Fix: CVE-2026-45597 Gives SYSTEM Access via UI Automation Bug
Microsoft's June 9, 2026 security update addresses a significant local elevation-of-privilege vulnerability tracked as CVE-2026-45597. The flaw resides in the Windows UI Automation Manager,...
June 2026 Patch Tuesday: Windows MotW Bypass CVE-2026-45595 Gets Fix
Microsoft has released a security update to address CVE-2026-45595, a Windows Mark of the Web (MotW) security feature bypass vulnerability, as part of the June 9, 2026 Patch Tuesday. The flaw, rated...
200 RCE bugs in June Patch Tuesday—patch Windows, Office, Azure now
Microsoft dropped its June 2026 Patch Tuesday release on June 9, packing fixes for roughly 200 disclosed vulnerabilities spanning Windows, Office, Azure, Exchange Online, Microsoft Graph, SQL Server,...
CVE-2026-42828: Windows ProjFS Flaw Lets Attackers Gain SYSTEM Rights
Microsoft’s June 2026 Patch Tuesday has delivered a critical fix for CVE-2026-42828, an elevation-of-privilege vulnerability in the Windows Projected File System (ProjFS). Rated Important with a...
CVE-2026-48576: Microsoft Secure Boot Bypass Threatens Boot Chain
Microsoft has officially disclosed a new Secure Boot security feature bypass vulnerability, tracked as CVE-2026-48576, through the MSRC Security Update Guide in June 2026. The advisory details a flaw...
June 2026 Windows Update Fixes CVE-2026-48573 Secure Boot Bypass
Microsoft's June 2026 Patch Tuesday rollout includes a fix for a Secure Boot feature bypass identified as CVE-2026-48573. The vulnerability, rated Important, could allow an attacker with local access...
CVE-2026-48570 Secure Boot bypass: Apply June 2026 Windows patches now
Microsoft released security updates on June 9, 2026 to close CVE-2026-48570, an Important-rated Windows Secure Boot security feature bypass. The flaw allows an attacker with either physical access or...
Patch Tuesday: Microsoft Fixes CVE-2026-48566 DWM Info Disclosure Flaw
Microsoft has disclosed a new information disclosure vulnerability in the Windows Desktop Window Manager (DWM) Core Library. Tracked as CVE-2026-48566, this Important-rated flaw was patched in the...
Microsoft Patch Tuesday June 2026: Fix Critical RDP Client RCE Flaw Now
Microsoft has patched a critical remote code execution flaw in the Windows Remote Desktop Client with its June 2026 Patch Tuesday release. Tracked as CVE-2026-48563, the vulnerability carries a...
RDP Client RCE CVE-2026-47653: Patch by June 9 to block full-system takeover
Microsoft dropped a critical remote code execution (RCE) vulnerability fix into its June 9, 2026 Patch Tuesday release. CVE-2026-47653 targets the Remote Desktop Client and carries a severity rating...
Microsoft Confirms CVE-2026-8863 UEFI Secure Boot Bypass: What Windows Users Need to Know
Microsoft officially acknowledged a critical vulnerability in the UEFI Secure Boot feature on June 9, 2026, with the publication of CVE-2026-8863 in its Security Update Guide. The advisory, still...
Microsoft Windows Storage EoP Flaw Grants SYSTEM Access—Patch Now
Microsoft dropped a security bombshell on June 9, 2026, with the publication of CVE-2026-47648, a critical elevation-of-privilege vulnerability burrowed deep inside the Windows Storage subsystem. The...