Patch Management
The latest Patch Management coverage — news, analysis, and updates from the WindowsNews.AI desk.
Per-Mailbox Cloud Management Lets Admins Finally Retire the Last Exchange Server
Microsoft has released a per‑mailbox cloud management feature that finally gives hybrid Exchange organizations a clear path to unplugging the last on‑premises Exchange server. With the new...
SharePoint, Cisco, Apple Zero-Days Headline 908-CVE Weekly Vulnerability Barrage
Security researchers tracked 908 new vulnerabilities in the last seven days, more than 188 of which already have publicly available proof-of-concept exploits, according to Cyble’s latest weekly...
Microsoft’s ESU Enrollment Wizard: Fixed but Still Hidden in Phased Rollout
Microsoft’s slow, staged rollout of the Windows 10 Extended Security Updates (ESU) enrollment wizard means the one-year security lifeline for legacy PCs is available—but not instantly visible to...
When Windows 11 Security Locked Out Valorant Players: The VAN9003 Error and How to Defeat It
For months, Valorant enthusiasts running Windows 11 have been ambushed by a frustrating error: VAN9003, accompanied by the message “This build of Vanguard is out of compliance with current system...
SSD Vanishing Act: Windows 11 KB5063878 Sparks Data Corruption Fears
The August 12, 2025 cumulative update for Windows 11 (KB5063878) is triggering a dangerous storage regression: under sustained heavy write workloads, some solid-state drives abruptly stop responding,...
Microsoft Silently Patches Copilot Audit Blind Spot That Allowed Silent Data Exfiltration
Microsoft quietly fixed a critical gap in Microsoft 365 Copilot’s audit logging in mid‑August 2025 after researchers proved that a simple prompt tweak could make the AI assistant summarize...
Microsoft Flags Critical Race Condition RCE in Windows Storage—Patch Immediately
Microsoft has issued a critical security advisory for CVE-2025-55231, a race‑condition vulnerability in the Windows storage management stack that could allow remote code execution. The flaw,...
Microsoft Fixes CVE-2025-55229 Certificate Spoofing Bug Threatening TLS, VPNs, and Code Signing
Microsoft this week disclosed CVE-2025-55229, a high-impact spoofing vulnerability in Windows certificate handling that allows attackers to bypass signature verification over a network. The flaw,...
Chrome 139 Seals High-Severity V8 Out-of-Bounds Write CVE-2025-9132, Enterprises Scramble to Patch Edge
Google on August 19 shipped Chrome 139.0.7258.138 to patch a high-severity out-of-bounds write in its V8 JavaScript engine, tracked as CVE-2025-9132, that could let attackers execute arbitrary code...
CVE-2025-53763: Microsoft Flags Azure Databricks Privilege Escalation Flaw, Urges Immediate Defensive Actions
Microsoft has disclosed a new privilege escalation vulnerability in Azure Databricks, tracked as CVE-2025-53763, which could allow an attacker with network access to elevate their privileges within...
Patch Now: Microsoft's netbt.sys Kernel Flaw (CVE-2025-55230/47996) Grants Attackers Full Control
A local elevation-of-privilege flaw in the Windows MBT Transport driver—the kernel component behind NetBIOS over TCP/IP—can hand attackers full SYSTEM rights, and while Microsoft’s July 2025...
PC Manager’s 7.8 CVSS Flaw Exposed: How Symlinks Give Attackers SYSTEM Rights
A vulnerability tracked as CVE-2025-29975 in Microsoft PC Manager hands local attackers a direct path to full SYSTEM control. With a CVSS 3.1 score of 7.8 (high) and a low attack complexity, the bug...