Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows Kernel Driver Bug CVE-2026-40369 Allows SYSTEM Access in May Patch Tuesday
Microsoft's May 2026 Patch Tuesday, released on May 12, includes a fix for CVE-2026-40369, an Important-rated elevation of privilege vulnerability in the Windows kernel-mode driver with a CVSS score...
CVE-2026-40367: Patch All Office Apps, Not Just Word, Microsoft Warns
Microsoft’s May 12, 2026 security updates addressed a critical remote code execution vulnerability in Microsoft Word tracked as CVE-2026-40367, but the patch deployment is unlike a typical Office...
Microsoft Issues Urgent Patch for Critical SharePoint Server 2019 RCE Flaw
Microsoft has released security updates to address a critical remote code execution vulnerability in SharePoint Server 2019, tracked as CVE-2026-40365. The patch, delivered via the SharePoint Server...
CVE-2026-40362: Patch Excel RCE flaw now before exploits surface
Microsoft’s Security Update Guide now lists CVE-2026-40362, a remote code execution (RCE) vulnerability in Microsoft Excel, with the company expressing high confidence in its existence and...
Patch Critical CVE-2026-40359 Excel RCE Flaw Now to Block Attacks
Microsoft has officially disclosed CVE-2026-40359, a remote code execution (RCE) vulnerability in Microsoft Excel, in its Security Update Guide. The listing marks it as an Office-family patching...
CVE-2026-40361: Microsoft Word Remote Code Execution Vulnerability Demands Immediate Patching
Microsoft has disclosed CVE-2026-40361, a remote code execution vulnerability in Microsoft Word, through its Security Update Guide on May 12, 2026. The advisory carries an urgent tone, starkly...
Patch Now: Microsoft Flags Critical Office RCE CVE-2026-40358 as High Risk
Microsoft dropped a bombshell in its May 2026 Patch Tuesday release, disclosing a critical remote code execution vulnerability in Microsoft Office that carries an unusually high confidence label for...
CVE-2026-40357 SharePoint RCE Exploit Warning: Patch Now or Risk Breach
Microsoft’s security advisory for CVE-2026-40357 isn’t just another patch note—it’s a klaxon. The SharePoint Server remote code execution vulnerability, listed in the May 2026 Security Update...
CVE-2026-34341: Windows LLDP Double-Free Bug Gives Attackers SYSTEM Access
Microsoft’s May 2026 Patch Tuesday shipped a fix for CVE-2026-34341, an Important-rated elevation-of-privilege vulnerability in the Windows Link-Layer Discovery Protocol. A low-privileged local...
CVE-2026-34340: Windows ProjFS Patch Fixes Critical EoP Flaw
Microsoft addressed a critical elevation-of-privilege (EoP) vulnerability in the Windows Projected File System (ProjFS) as part of its May 2026 Patch Tuesday updates. The flaw, tracked as...
Microsoft fixes CVE-2026-34339: Patch LDAP DoS flaw to prevent domain controller crashes
Microsoft dropped a critical patch for CVE-2026-34339 in its May 12, 2026 Patch Tuesday release, addressing a denial-of-service vulnerability in the Windows Lightweight Directory Access Protocol...
Apply May 2026 Patch for Windows Telephony EoP Flaw CVE-2026-34338
On May 12, 2026, Microsoft published details on CVE-2026-34338, a new elevation-of-privilege (EoP) vulnerability affecting the Windows Telephony Service. The disclosure arrived as part of the...