Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Microsoft’s Critical Kerberos DoS CVE-2026-42914 on Domain Controllers
Microsoft’s June 2026 Patch Tuesday landed on June 9 with a particularly disruptive vulnerability in its belt. CVE-2026-42914, an Important-rated Windows Kerberos denial-of-service flaw, threatens...
Microsoft’s June 2026 Patch Fixes Windows Telephony Service Privilege Escalation Bug
Microsoft disclosed CVE-2026-42912 on June 9, 2026, as part of its monthly security update cycle. This elevation-of-privilege vulnerability in the Windows Telephony Service stems from a race...
CVE-2026-42911: Windows AFD.sys Privilege Escalation Flaw Patched in June 2026 Update
Microsoft released a patch on June 9, 2026, for CVE-2026-42911, an Important-rated elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). The flaw could...
CVE-2026-42913: High-Severity RDP Client RCE Flaw Hits Windows 11 and Server — What You Must Do Now
Microsoft on June 9, 2026, disclosed CVE-2026-42913, a critical remote code execution vulnerability in the Remote Desktop Protocol (RDP) client, affecting Windows 11, Windows Server 2022, and Windows...
Windows Kernel Flaw CVE-2026-42916: Patch Now to Block Full SYSTEM Takeover
Microsoft’s June 2026 Patch Tuesday delivered a fix for CVE-2026-42916, a high-severity elevation-of-privilege vulnerability lurking in the Windows NT OS Kernel. Disclosed on June 9, 2026, this...
CVE-2026-42909: Patch Windows RDP Client Now, Block Outbound RDP
Microsoft dropped a potentially disruptive remote code execution advisory this Patch Tuesday that should stop every Windows admin in their tracks. CVE-2026-42909, rated Important, is a bug in the...
CVE-2026-42980: Patch Critical NT Kernel EoP Bug Now (CVSS 7.8)
Microsoft dropped its June 2026 Patch Tuesday updates on June 9, addressing a total of 67 vulnerabilities across the Windows ecosystem. Among them, CVE-2026-42980 stands out as a local...
Microsoft Patches Critical RDP Info Disclosure Bug CVE-2026-42908 Now
Microsoft patched a critical information disclosure bug in Windows Remote Desktop Services as part of its June 2026 security updates. CVE-2026-42908, an out-of-bounds read vulnerability, allows an...
Windows Shell Memory Leak Patch: Why June 2026's Medium Bug Is Critical
Microsoft's June 2026 Patch Tuesday touched down on the 9th, and tucked inside the usual monthly cavalcade of fixes was CVE-2026-42907, a medium-severity information disclosure vulnerability in the...
Windows TCP/IP Zero-Click Flaw Lets Attackers Gain SYSTEM Access
Microsoft’s June 2026 Patch Tuesday batch fixes a critical Windows networking flaw—CVE-2026-42904—that lets unauthenticated attackers escalate privileges to SYSTEM, the highest possible level...
CVE-2026-42903: Critical Kerberos Denial-of-Service Flaw Patched – Update Windows Domain Controllers Immediately
Microsoft has released a security update that patches CVE-2026-42903, a denial-of-service vulnerability in the Kerberos authentication protocol, as part of the June 2026 Patch Tuesday cycle. The...
ProjFS bug CVE-2026-42837 lets local attackers escalate to SYSTEM via kernel buffer over-read
Microsoft's June 2026 security update addresses CVE-2026-42837, a local privilege escalation vulnerability in the Windows Projected File System (ProjFS) filter driver. An attacker who successfully...