Live
Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow·MSFT +2.1%CVE-2026-42896: Microsoft Urges SYSTEM-Level EoP Patch for DWM Core Library·NVDA +0.2%Microsoft Patches Rich Text Edit Control Privilege Escalation (CVE-2026-32170) in May 2026 Patch Tuesday·GOOGL +1.7%CVE-2026-32161: Windows WiFi Miniport RCE Flaw – Why You Must Patch Immediately·AMZN +1.1%CVE-2026-41088: Microsoft Patches AFD.sys Elevation of Privilege Vulnerability in May 2026 Patch Tuesday·MSFT +2.1%CVE-2026-40415: Patch Critical Windows TCP/IP RCE Flaw Now·NVDA +0.2%CVE-2026-40414: Microsoft Fixes Important TCP/IP Null Pointer DoS Flaw in May 2026 Patch Tuesday·GOOGL +1.7%Windows WAN ARP Driver Use-After-Free Flaw Grants SYSTEM Access·AMZN +1.1%Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow·MSFT +2.1%CVE-2026-42896: Microsoft Urges SYSTEM-Level EoP Patch for DWM Core Library·NVDA +0.2%Microsoft Patches Rich Text Edit Control Privilege Escalation (CVE-2026-32170) in May 2026 Patch Tuesday·GOOGL +1.7%CVE-2026-32161: Windows WiFi Miniport RCE Flaw – Why You Must Patch Immediately·AMZN +1.1%CVE-2026-41088: Microsoft Patches AFD.sys Elevation of Privilege Vulnerability in May 2026 Patch Tuesday·MSFT +2.1%CVE-2026-40415: Patch Critical Windows TCP/IP RCE Flaw Now·NVDA +0.2%CVE-2026-40414: Microsoft Fixes Important TCP/IP Null Pointer DoS Flaw in May 2026 Patch Tuesday·GOOGL +1.7%Windows WAN ARP Driver Use-After-Free Flaw Grants SYSTEM Access·AMZN +1.1%

Windows Security

The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 8:25 AM
Latest Most Read Breaking
Sort
Cve-2026-33837 · Privilege Escalation

Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow

CVE-2026-33837 landed on the May 2026 Patch Tuesday with an Important severity rating. It’s a local elevation-of-privilege vulnerability inside tcpip.sys, the kernel-mode driver that handles the...

Advertisement
cve_2026_41088_microsoft.jpg
Afd Sys · Cve-2026-41088

CVE-2026-41088: Microsoft Patches AFD.sys Elevation of Privilege Vulnerability in May 2026 Patch Tuesday

Microsoft shipped a security update on May 12, 2026, to plug a local elevation-of-privilege hole in the Windows Ancillary Function Driver for Winsock (AFD.sys). The vulnerability, tracked as...

SE Security Desk·10w ago
Patch Tuesday · Tcp/ip Rce

CVE-2026-40415: Patch Critical Windows TCP/IP RCE Flaw Now

Microsoft disclosed a critical remote code execution vulnerability in the Windows TCP/IP stack on May 12, 2026, assigned CVE-2026-40415. The flaw, detailed in the monthly Security Update Guide, sits...

SE Security Desk·10w ago
cve_2026_40414_microsoft.jpg
Hyper-v · Patch Management

CVE-2026-40414: Microsoft Fixes Important TCP/IP Null Pointer DoS Flaw in May 2026 Patch Tuesday

Microsoft's May 2026 Patch Tuesday landed with a notable fix for CVE-2026-40414, an Important-rated denial-of-service vulnerability in the Windows TCP/IP stack. The flaw, caused by a NULL pointer...

SE Security Desk·10w ago
windows_wan_arp_driver.jpg
Cve-2026-40408 · Kernel Use-after-free

Windows WAN ARP Driver Use-After-Free Flaw Grants SYSTEM Access

Microsoft disclosed CVE-2026-40408 on May 12, 2026, as part of its monthly Patch Tuesday security updates. This Important-rated elevation-of-privilege vulnerability resides in the Windows WAN ARP...

SE Security Desk·10w ago
cve_2026_40380_critical.jpg
Cve-2026-40380 · Patch Tuesday

CVE-2026-40380: Critical Windows Volume Manager RCE Vulnerability Patched in May 2026 Update

Microsoft shipped a critical security fix for CVE-2026-40380 in its May 2026 Patch Tuesday release, closing a remote code execution vulnerability in the Windows Volume Manager Extension Driver. The...

SE Security Desk·10w ago
cve_2026_40374_microsoft.jpg
Cve-2026-40374 · Information Disclosure

CVE-2026-40374: Microsoft Patches Power Automate Desktop Information Disclosure Bug

Microsoft has published a new security advisory for a confirmed information disclosure vulnerability in Power Automate Desktop, tracked as CVE-2026-40374. The announcement came via the company’s...

SE Security Desk·10w ago
Cloud Files · Cve-2026-35418

Microsoft Patches CVE-2026-35418: Elevation-of-Privilege in Windows Cloud Files Driver

On May 12, 2026, Microsoft disclosed CVE-2026-35418, a serious elevation-of-privilege vulnerability that affects the Windows Cloud Files Mini Filter Driver. The flaw, which received an \"Important\"...

SE Security Desk·10w ago
microsoft_confirms_critical_windows.jpg
Cve Remediation · Privilege Escalation

Microsoft Confirms Critical Windows Storage Spaces EoP Flaw—Patch Now

Microsoft dropped a stark warning this week: CVE-2026-35415 is not a drill. The vulnerability in Windows Storage Spaces Controller could hand attackers full system control, and the clock is ticking...

SE Security Desk·10w ago