Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Urgent June 2026 Patch Tuesday: Fix Critical SharePoint Spoofing Bug Now
Microsoft’s June 2026 Patch Tuesday release, dropped on June 9, hides a nasty surprise for SharePoint on‑premises administrators: CVE‑2026‑47641, a spoofing vulnerability that could let...
Patch Missing Details: CVE-2026-47637 Spoofing Threat Hits SharePoint Server
Microsoft has published a new security advisory for CVE-2026-47637, flagging a spoofing vulnerability in SharePoint Server. The listing appeared in the company's Security Update Guide with a note...
Microsoft Patches SharePoint Server Spoofing Vulnerability CVE-2026-47636 in June 2026 Update
Microsoft’s June 2026 Patch Tuesday rollout includes a fix for a spoofing vulnerability in SharePoint Server, tracked as CVE-2026-47636. The vulnerability, disclosed on June 9, 2026, affects...
Urgent Patching: 3 Actively Exploited Flaws Added to CISA KEV on June 9
CISA’s Known Exploited Vulnerabilities (KEV) Catalog swelled by three new entries on June 9, 2026, each confirmed to be under active attack. CVE-2026-7473 in Arista EOS, CVE-2026-11645 in Google...
Urgent SharePoint RCE: CVE-2026-47298 Patched in June 2026 Patch Tuesday Release
Microsoft released a critical out-of-band security update on June 9, 2026, addressing a remote code execution vulnerability in SharePoint Server Subscription Edition tracked as CVE-2026-47298. The...
AKS Operators: Patch Critical RCE Flaw CVE-2026-32193 Now
CVE-2026-32193 is a remote code execution vulnerability in Azure Kubernetes Service (AKS) that Microsoft just disclosed in its Security Update Guide. If you run workloads on AKS, you need to act...
Patch VS Code Now: CVE-2026-47292 RCE in MSSQL Extension Hits Developer Workbenches
Microsoft has assigned CVE-2026-47292 to a remote code execution (RCE) vulnerability residing in the Visual Studio Code MSSQL extension, marking the first time this popular database tool has been...
Microsoft Patches Critical Kinect Flaw Allowing Local Privilege Escalation to SYSTEM
Microsoft released a security update on June 9, 2026, addressing CVE-2026-41092, an Important-rated elevation-of-privilege vulnerability in Microsoft Kinect. The flaw stems from improper access...
CVE-2026-47291: Patch Critical Windows HTTP.sys RCE Now
Microsoft has released a security update to address CVE-2026-47291, a critical remote code execution vulnerability in the Windows HTTP Protocol Stack (HTTP.sys) that impacts all supported editions of...
Patch Microsoft RDP Client Now: Critical CVE-2026-47289 Admin Risk
Microsoft has issued a security advisory for CVE-2026-47289, a critical remote code execution vulnerability in the Windows Remote Desktop Protocol (RDP) client. Disclosed on June 9, 2026, through the...
Microsoft Patches CVE-2026-47288, a Critical Kerberos KDC RCE Exploit Threatening Windows Server Domain Controllers
Microsoft released an out-of-band security update on June 9, 2026, addressing CVE-2026-47288, a critical remote code execution vulnerability in the Kerberos Key Distribution Center (KDC) on Windows...
CVE-2026-47287: VS Code Tampering Flaw Puts Developer Supply Chains at Risk
Microsoft published a new security advisory on June 9, 2026, flagging a tampering vulnerability in Visual Studio Code that strikes at the heart of the developer toolchain. CVE-2026-47287, as...