Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Azure Linux Admins: Patch Memcached CVE-2026-47783 Before Data Leaks
Microsoft has issued a stark warning to Azure Linux 3.0 users: update the memcached package immediately or risk exposing sensitive data through a critical timing side-channel vulnerability. The flaw,...
CVE-2026-47784 Memcached Attack: Patch Windows Instances Now
A critical timing side channel vulnerability, tracked as CVE-2026-47784, was disclosed on May 20, 2026, affecting all memcached versions before 1.6.42. The flaw allows an attacker to brute-force SASL...
Pip 26.1 Patches CVE-2026-6357 Import Bug Threatening Windows Supply Chains
pip version 26.1 patches a medium-severity vulnerability that could have allowed malicious code execution during routine package installations. The flaw, tracked as CVE-2026-6357 and disclosed in...
Apply May 2026 Windows Update to Fix Unbound DNS Crash Vulnerability
Microsoft has patched a denial-of-service vulnerability in the NLnet Labs Unbound DNS resolver that could let an attacker crash Windows servers or cause severe performance degradation with a single...
Unbound DNS CVE-2026-42944 Heap Overflow Fixed in 1.25.1
NLnet Labs has released Unbound version 1.25.1 to address CVE-2026-42944, a high-severity heap-based buffer overflow vulnerability in its popular DNS resolver software. The flaw, disclosed on May 20,...
Unbound DNS Flaw CVE-2026-40622 Resurrects Revoked Ghost Domains, Fixed in 1.25.1
NLnet Labs dropped a security advisory on May 20, 2026, warning that a medium-severity bug in Unbound can keep revoked domain names alive in resolver caches long after they should have expired. The...
Unbound DNS Bug CVE-2026-42534 Slows Windows Networks, Patch Now
NLnet Labs disclosed CVE-2026-42534 on May 20, 2026, a medium-severity vulnerability in the Unbound DNS resolver that allows attackers to degrade DNS performance on Windows networks. The flaw,...
CVE-2026-41292: Unbound DNS Resolver Flawed by Malformed EDNS Options, Patch Now
A critical remote denial-of-service vulnerability in the widely used Unbound DNS resolver was disclosed on May 20, 2026, by NLnet Labs. Tracked as CVE-2026-41292, the flaw affects all Unbound...
Rsync Patched: Fix Critical Symlink Race in Daemon Mode for Windows Admins
A high-severity vulnerability in rsync, tracked as CVE-2026-29518, exposes daemons running without chroot protection to a symlink race condition. Disclosed on May 20, 2026, the flaw affects all rsync...
CVE-2026-45232: Rsync Proxy Bug Patched in 3.4.3, Low Severity but High Ops Risk
The rsync project has patched a freshly disclosed vulnerability, CVE-2026-45232, that lurks in the proxy handling logic of clients using the RSYNC_PROXY environment variable. Assigned a Low severity...
Fix Rsync Now: DNS Reverse Spoofing Bypasses Host Deny Rules in 3.4.2
On May 20, 2026, a medium-severity authorization bypass vulnerability, tracked as CVE-2026-43617, was disclosed for the widely-used rsync file synchronization tool. The flaw affects rsync daemon...
Microsoft MSRC Reveals Unbound CVE-2026-42923: NSEC3 Hash Attack Hits Windows DNS Resolvers
Microsoft’s Security Response Center has published details of CVE-2026-42923, a degradation-of-service vulnerability in NLnet Labs Unbound, the widely used open-source DNS recursive resolver....