Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow
CVE-2026-33837 landed on the May 2026 Patch Tuesday with an Important severity rating. It’s a local elevation-of-privilege vulnerability inside tcpip.sys, the kernel-mode driver that handles the...
CVE-2026-42896: Microsoft Urges SYSTEM-Level EoP Patch for DWM Core Library
Microsoft has published a critical security advisory for CVE-2026-42896, an elevation-of-privilege vulnerability in the Windows Desktop Window Manager (DWM) Core Library. The flaw allows a locally...
Microsoft Patches Rich Text Edit Control Privilege Escalation (CVE-2026-32170) in May 2026 Patch Tuesday
Microsoft's May 12, 2026 Patch Tuesday release addresses CVE-2026-32170, an elevation-of-privilege vulnerability in the Windows Rich Text Edit Control. The flaw, disclosed in the Microsoft Security...
CVE-2026-32161: Windows WiFi Miniport RCE Flaw – Why You Must Patch Immediately
Microsoft has disclosed a critical remote code execution vulnerability that weaponizes Wi‑Fi signals to hijack Windows devices. Tracked as CVE-2026-32161, the flaw resides in the Windows Native...
CVE-2026-41088: Microsoft Patches AFD.sys Elevation of Privilege Vulnerability in May 2026 Patch Tuesday
Microsoft shipped a security update on May 12, 2026, to plug a local elevation-of-privilege hole in the Windows Ancillary Function Driver for Winsock (AFD.sys). The vulnerability, tracked as...
CVE-2026-40415: Patch Critical Windows TCP/IP RCE Flaw Now
Microsoft disclosed a critical remote code execution vulnerability in the Windows TCP/IP stack on May 12, 2026, assigned CVE-2026-40415. The flaw, detailed in the monthly Security Update Guide, sits...
CVE-2026-40414: Microsoft Fixes Important TCP/IP Null Pointer DoS Flaw in May 2026 Patch Tuesday
Microsoft's May 2026 Patch Tuesday landed with a notable fix for CVE-2026-40414, an Important-rated denial-of-service vulnerability in the Windows TCP/IP stack. The flaw, caused by a NULL pointer...
Windows WAN ARP Driver Use-After-Free Flaw Grants SYSTEM Access
Microsoft disclosed CVE-2026-40408 on May 12, 2026, as part of its monthly Patch Tuesday security updates. This Important-rated elevation-of-privilege vulnerability resides in the Windows WAN ARP...
CVE-2026-40380: Critical Windows Volume Manager RCE Vulnerability Patched in May 2026 Update
Microsoft shipped a critical security fix for CVE-2026-40380 in its May 2026 Patch Tuesday release, closing a remote code execution vulnerability in the Windows Volume Manager Extension Driver. The...
CVE-2026-40374: Microsoft Patches Power Automate Desktop Information Disclosure Bug
Microsoft has published a new security advisory for a confirmed information disclosure vulnerability in Power Automate Desktop, tracked as CVE-2026-40374. The announcement came via the company’s...
Microsoft Patches CVE-2026-35418: Elevation-of-Privilege in Windows Cloud Files Driver
On May 12, 2026, Microsoft disclosed CVE-2026-35418, a serious elevation-of-privilege vulnerability that affects the Windows Cloud Files Mini Filter Driver. The flaw, which received an \"Important\"...
Microsoft Confirms Critical Windows Storage Spaces EoP Flaw—Patch Now
Microsoft dropped a stark warning this week: CVE-2026-35415 is not a drill. The vulnerability in Windows Storage Spaces Controller could hand attackers full system control, and the clock is ticking...