Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows June 2026 Update Closes UxTheme Loop: A Visual Engine Crash That Local Attackers Can Trigger
On June 9, 2026, Microsoft disclosed and patched a denial-of-service flaw in the Windows UxTheme Library, the system component responsible for drawing themed controls and window chrome....
Patch Your Windows Now: Critical Bluetooth Driver EoP Bug CVE-2026-45640
Microsoft has acknowledged a new elevation-of-privilege (EoP) vulnerability, tracked as CVE-2026-45640, affecting the Windows Bluetooth Port Driver. Disclosed through the Microsoft Security Response...
Critical RDP Memory Leak: Unauthenticated Attackers Can Read Server Secrets
Microsoft has confirmed a new information disclosure vulnerability in the Windows Remote Desktop Protocol (RDP) that could allow unauthenticated attackers to read sensitive memory contents from...
Microsoft Patches CVE-2026-45605 Windows Bluetooth Use-After-Free Flaw
Microsoft patched a critical elevation-of-privilege vulnerability in the Windows Bluetooth Service on June 9, 2026, closing a use-after-free bug that could allow attackers to gain SYSTEM-level...
CVE-2026-45491: Critical .NET Tampering Flaw Demands Immediate Windows Patching
Microsoft’s Security Update Guide confirmed a new .NET tampering vulnerability on June 9, 2026, but the advisory left security teams with more questions than answers. The sparse public record for...
.NET SDK zero-day CVE-2026-45490 threatens build pipelines with privilege escalation
Microsoft’s June 2026 Patch Tuesday updates include a new elevation-of-privilege vulnerability tracked as CVE-2026-45490 that affects the .NET SDK, potentially putting developer pipelines and...
Windows PCA Bug Lets Local Attackers Seize SYSTEM Rights—Patch Now
Microsoft has disclosed a local elevation-of-privilege (EoP) vulnerability in the Windows Program Compatibility Assistant (PCA) Service, tracked as CVE-2026-45487. The advisory, released on June 9,...
Microsoft Word Info Disclosure CVE-2026-45466 Demands Swift Enterprise Triage This Patch Tuesday
Microsoft dropped a critical security advisory on June 9, 2026, tagging CVE-2026-45466 as an information disclosure vulnerability in Microsoft Word. The flaw, disclosed as part of the monthly Patch...
Mac Office admins: No patch yet for CVE-2026-45460 critical RCE flaw—act now
Microsoft dropped an unwelcome surprise on Mac administrators Monday with the publication of CVE-2026-45460. The advisory, issued June 9, 2026, warns of a critical vulnerability in Microsoft Office...
Microsoft Office RCE CVE-2026-45461: Why Local Attack Vector Still Means Remote Risk
CVE-2026-45461 landed in Microsoft’s June 9, 2026 Patch Tuesday as a Critical-rated remote code execution vulnerability in Microsoft Office. The flaw, which carries a CVSS v3.1 base score of 9.8,...
CVE-2026-45456: Remote Code Execution with CVSS AV:L – Why Microsoft and CVSS Disagree
A newly published vulnerability identifier, CVE-2026-45456, has set off discussion among security professionals because of a seemingly contradictory classification: Microsoft labels it as “Remote...
CVE-2026-45458: The Outlook and Word RCE That Turns Emails Into Attack Vectors
Microsoft’s security team dropped a critical advisory for CVE-2026-45458 this Patch Tuesday, sending IT admins scrambling to assess the damage. The flaw, rated 8.4 on the CVSS scale, enables remote...