Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Linux Kernel Bluetooth Zero-Day Exploits WSL2 and Azure VMs
A high-severity vulnerability in the Linux kernel’s Bluetooth stack, tracked as CVE-2026-31771, was publicly disclosed on May 1, 2026. The flaw exposes millions of devices—including those running...
Linux Kernel CVE-2026-43036 Leaks Memory via TCP GSO Packet Flaw
A medium-severity vulnerability in the Linux kernel’s network stack exposes systems to a subtle information leak, exploiting the way the kernel handles segmented TCP packets. CVE-2026-43036,...
CVE-2026-31724: Linux Kernel USB Gadget Flaw Causes DoS — No Risk to Windows
The Linux kernel’s security team has published details of a newly assigned vulnerability, CVE-2026-31724, that targets the USB gadget subsystem. The flaw, rated medium severity, resides in the...
CVE-2026-31723: Linux Kernel Patch Fixes Dangling sysfs Links in USB Gadget Driver – Why Windows Users Should Care
A new Linux kernel vulnerability, CVE-2026-31723, has been disclosed, drawing attention to a subtle bug in the USB gadget subsystem's f_subset driver. Published on May 1, 2026, the medium-severity...
CISA Adds Critical LiteLLM SQL Injection Flaw (CVE-2026-42208) to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency on May 8, 2026, added a critical SQL injection vulnerability in BerriAI’s LiteLLM AI proxy to its Known Exploited Vulnerabilities Catalog....
CVE-2026-42826: Why Report Confidence Is Key for Azure DevOps Risk
Microsoft's Security Update Guide lists CVE-2026-42826 as an Azure DevOps information disclosure vulnerability, and while the technical details are still emerging, the conversation it started has...
Microsoft Silently Fixes Azure Cloud Shell Flaw Allowing Session Hijacking
Microsoft has neutralized a critical spoofing vulnerability in Azure Cloud Shell that could have allowed attackers to inject malicious commands and impersonate users inside the browser-based...
CVE-2026-35435: Critical Azure AI Foundry Privilege Escalation in M365 Agents Leaves Systems Vulnerable
Microsoft has disclosed a critical elevation-of-privilege vulnerability in Azure AI Foundry, tracked as CVE-2026-35435, which affects Microsoft 365 published agents and currently has no patch....
CVE-2026-34327: Partner Center Spoofing Exposes Trust Boundaries in Cloud Admin
Microsoft’s Security Response Center has disclosed CVE-2026-34327, a spoofing vulnerability residing in the Microsoft Partner Center. The advisory, released in 2026, brings sharp focus to the...
CVE-2026-33844: Critical Azure Cassandra RCE Auto-Fixed by Microsoft
Microsoft published CVE-2026-33844 on May 7, 2026, revealing a critical remote code execution (RCE) vulnerability in its Azure Managed Instance for Apache Cassandra service. The flaw, stemming from...
CVE-2026-33823: Microsoft Teams Events Portal Flaw Exposes Sensitive Data—Report Confidence Kept It Hidden
Microsoft has officially assigned CVE-2026-33823 to an information disclosure vulnerability lurking in the Microsoft Teams Events Portal, a move that underscores the delicate balance between...
Azure ML Notebook Spoofing CVE: Why Sparse Advisories Demand Urgent Action
Microsoft's Security Update Guide has quietly listed a new vulnerability, CVE-2026-32207, affecting Azure Machine Learning Notebooks. The advisory frames it as a spoofing flaw and nothing more. No...