Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA Issues Emergency Warning as FortiBleed Exploits FortiGate SSL VPN Credentials to Target Windows Domains
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on June 18, 2026, warning organizations worldwide that attackers are actively exploiting compromised...
CISA Sounds Alarm on Unpatched Mitsubishi Electric DoS Flaw in All FX5-ENET/IP Modules
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has republished an advisory for CVE-2026-8806, a high-severity denial-of-service vulnerability that affects every version of...
Mitsubishi Electric Patches Critical CVE-2026-8805 DoS Vulnerability in FX5-EIP EtherNet/IP Modules
Mitsubishi Electric, in coordination with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), disclosed on June 18, 2026, that a remotely exploitable denial-of-service (DoS)...
CISA Alert: Schneider Electric OT Gear Vulnerable to Session Prediction Attacks (CVE-2026-4827)
CISA has urged critical infrastructure operators to immediately patch multiple Schneider Electric power automation products after discovering a session management vulnerability that could let...
Unpatched DAQFactory Type-Confusion Bug Turns .ctl Files into Code Execution Weapons
Industrial organizations received an urgent wake-up call on June 18, 2026, when the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory ICSA-26-169-02. The advisory warns...
CISA Flags Critical Authentication Bypass and DoS Flaws in Rockwell FactoryTalk Historian
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding three serious vulnerabilities in Rockwell Automation’s FactoryTalk Historian Site Edition (SE),...
CISA Flags Critical 9.8-Severity Code Execution Flaw in AVer PTC Cameras Used Worldwide
The Cybersecurity and Infrastructure Security Agency (CISA) published advisory ICSA-26-169-01 on June 18, 2026, alerting organizations to a maximum-severity vulnerability in multiple AVer PTC camera...
CVE-2026-6865: Schneider Electric’s EasyLogic and Saitel RTUs Exposed to File Theft via Path Traversal Bug
Schneider Electric and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are urging critical infrastructure operators to immediately patch a path traversal vulnerability that exposes...
Patch Now: CISA Confirms Active Exploitation of Splunk CVE-2026-20253
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20253, a critical missing-authentication vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities...
Apollo Glucose Meter's Bluetooth Holes Could Leak Sensitive Health Data, CISA Warns
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) dropped a medical device advisory on June 18, 2026, flagging serious Bluetooth vulnerabilities in a widely used diabetes management...
CVE-2026-25680: Go HTML Parser Flaw Triggers DoS Alert for Windows Server Administrators
Windows administrators are scrambling to assess their exposure after a high-severity vulnerability was disclosed in Go’s golang.org/x/net library on May 22, 2026. CVE-2026-25680 allows an...
Microsoft Flags Medium XSS Bug in Go x/net/html After May 2026 Patch
Microsoft has published CVE-2026-25681, officially tracking a medium-severity cross-site scripting (XSS) flaw in the popular Go library golang.org/x/net/html. The advisory arrives on the heels of the...