Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Holds Back Technical Details on Azure Portal Admin Center Privilege Escalation Flaw
Microsoft’s Security Response Center (MSRC) has published CVE-2026-41086, an elevation-of-privilege vulnerability affecting the Windows Admin Center experience integrated into the Azure Portal. The...
Patch Tuesday Fix: CVE-2026-40420 Lets Local Users Escalate Office Click-To-Run to SYSTEM
Microsoft has disclosed CVE-2026-40420, an Important-rated elevation-of-privilege vulnerability in Microsoft Office Click-To-Run, the core deployment and update technology for Microsoft 365 Apps for...
CVE-2026-35436: Microsoft Patches Important Office Click-to-Run Elevation-of-Privilege Flaw
Microsoft rolled out its scheduled Patch Tuesday updates for May 2026, addressing a newly disclosed elevation-of-privilege vulnerability in Office Click-to-Run. CVE-2026-35436, rated Important, could...
CVE-2026-40418: Microsoft Office Click-to-Run Elevation of Privilege Flaw Patched in May 2026 Update
Microsoft's May 2026 Patch Tuesday, released on May 12, 2026, addressed CVE-2026-40418, an elevation-of-privilege vulnerability in Microsoft Office Click-to-Run. Rated Important, this security flaw...
Patch Now: May 2026 Fix for Windows TCP/IP DoS Bug CVE-2026-40413
Microsoft has released a critical security update addressing a denial-of-service vulnerability in the Windows TCP/IP stack, tracked as CVE-2026-40413, as part of its May 2026 Patch Tuesday rollout....
Patch Now: Critical CVE-2026-40403 Win32K RCE Hits All Windows
Microsoft’s May 2026 Patch Tuesday brought with it a critical disclosure that should jolt every Windows administrator into action: CVE-2026-40403, a remote code execution flaw in the Win32K...
Hyper-V Guest-to-Host Escape: Patch Critical CVE-2026-40402 Now
Microsoft’s May 2026 Patch Tuesday landed with a critical security update that Hyper-V administrators cannot afford to ignore. CVE-2026-40402, a use-after-free vulnerability in the Windows Hyper-V...
Windows Hyper-V Bug Lets Guest VM Crash Host via TCP/IP DoS
Microsoft’s May 2026 Patch Tuesday landed with a particularly nasty surprise for Hyper-V administrators: a denial-of-service vulnerability in the Windows TCP/IP stack that can bleed from a guest...
Microsoft patched CVE-2026-40398 in May 2026, an Important privilege escalation vulnerability in Windows Remote Desktop Services that allows a low-privileged authenticated attacker to gain SYSTEM priv
Microsoft's May 2026 Patch Tuesday rollout addressed 78 security vulnerabilities, among them CVE-2026-40398—an elevation-of-privilege bug in Windows Remote Desktop Services (RDS) scored at CVSS 7.8...
CVE-2026-32209: Microsoft Patches Critical Windows Filtering Platform Bypass in May 2026 Patch Tuesday
Microsoft dropped its May 2026 Patch Tuesday on May 12, and among the slew of fixes sits CVE-2026-32209 — a nasty security feature bypass in the Windows Filtering Platform (WFP). Public reporting...
Microsoft May Patch Tuesday Fixes Critical CLFS Elevation of Privilege Bug
Microsoft’s May 12, 2026 Patch Tuesday includes a fix for CVE-2026-40397, an Important-severity elevation-of-privilege vulnerability in the Windows Common Log File System (CLFS) driver. Public...
CVE-2026-40382: Critical Elevation of Privilege Flaw in Windows Telephony Service Patched
Microsoft’s May 2026 Patch Tuesday rollout brought a fix for CVE-2026-40382, an elevation-of-privilege vulnerability buried in the Windows Telephony Service. The disclosure, published in the...