Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch VS Code now: CVE-2026-40376 lets attackers hijack Azure identities via MCP flaw
{ "title": "VS Code CVE-2026-40376: Patch 1.119.1 and Audit MCP Managed Identity Risk", "content": "Microsoft has released Visual Studio Code version 1.119.1 to patch CVE-2026-40376, an...
CVE-2026-42835: High-Severity Microsoft Teams for Android Information Disclosure Vulnerability Patched in June 2026 Patch Tuesday
Microsoft has disclosed a high-severity information disclosure vulnerability in Microsoft Teams for Android, tracked as CVE-2026-42835, as part of its June 2026 Patch Tuesday updates. The...
June 2026 Patch Tuesday Fixes CVE-2026-42829: Silent Admin Rights Bypass in Windows 11 24H2+
Microsoft disclosed a security feature bypass vulnerability in Windows 11’s Administrator Protection on June 9, 2026, issuing patches for all supported versions. Tracked as CVE-2026-42829, the flaw...
CVE-2026-42828: Windows ProjFS Flaw Lets Attackers Gain SYSTEM Rights
Microsoft’s June 2026 Patch Tuesday has delivered a critical fix for CVE-2026-42828, an elevation-of-privilege vulnerability in the Windows Projected File System (ProjFS). Rated Important with a...
Patch Tuesday Urgent: Fix CVE-2026-40371 EoP in Dynamics 365 On-Prem
{ "title": "CVE-2026-40371: Patch Tuesday EoP Risk in Microsoft Dynamics 365 On-Prem", "content": "On June 9, 2026, Microsoft dropped a security advisory for CVE-2026-40371 as part of its...
Microsoft Warns: Patch Critical SharePoint Spoofing Bug CVE-2026-33113 Now
Microsoft disclosed CVE-2026-33113 on June 9, 2026, a spoofing vulnerability in on-premises Microsoft SharePoint Server. The advisory, published through the company’s Security Update Guide, warns...
Microsoft: Patch Nuance PowerScribe RCE Flaw CVE-2026-26142 Now
Microsoft’s June 2026 Patch Tuesday brought a stark warning for healthcare organizations: CVE-2026-26142, a critical remote code execution (RCE) vulnerability in Nuance PowerScribe and PowerScribe...
Microsoft Patches Windows Kernel Elevation-of-Privilege Flaw CVE-2026-48583 in June 2026 Patch Tuesday
Microsoft has pushed out a fix for a use-after-free vulnerability in the Windows kernel as part of its June 2026 security updates. Tracked as CVE-2026-48583, the local elevation-of-privilege flaw...
Security feature bypass flaw in Microsoft PC Manager gets Important severity in June 2026 Patch Tuesday.
Microsoft’s June 2026 Patch Tuesday release disclosed CVE-2026-49161, an Important-rated security feature bypass vulnerability in Microsoft PC Manager. The flaw, made public on June 9, 2026, allows...
CVE-2026-48578: Patch Tuesday Fix Closes Secure Boot Bypass for Bootkit Attacks
Microsoft dropped its June 2026 Patch Tuesday updates, and one vulnerability stands out: CVE-2026-48578. This Important-rated Secure Boot security feature bypass lets a highly privileged local...
CVE-2026-48576: Microsoft Secure Boot Bypass Threatens Boot Chain
Microsoft has officially disclosed a new Secure Boot security feature bypass vulnerability, tracked as CVE-2026-48576, through the MSRC Security Update Guide in June 2026. The advisory details a flaw...
Microsoft Patches CVE-2026-48575 Secure Boot Bypass in June 2026 Update
Microsoft has patched a critical Secure Boot bypass vulnerability tracked as CVE-2026-48575, issuing fixes in its June 2026 Patch Tuesday update. The flaw, rated Important, allows a locally...