Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-43126 in Linux ALSA OSS: Patch Sound Card Removal UAF.
Linux kernel developers have disclosed CVE-2026-43126, a use-after-free vulnerability buried in the ALSA OSS mixer compatibility code. The bug, published on May 6, 2026, stems from missing disconnect...
Linux kernel AMD GPU bug (CVE-2026-43131) crashes systems when SMU disabled; Windows admins must patch WSL2, VMs.
A newly patched vulnerability in the Linux kernel’s AMDGPU driver could crash systems with certain AMD GPUs when the System Management Unit (SMU) is disabled. CVE-2026-43131, disclosed on May 6,...
CVE-2026-43176 Patched: Linux rtw89 Fix Prevents Wi-Fi Driver Crashes
A severe vulnerability in the Linux kernel’s rtw89 Wi-Fi driver for Realtek PCI chips could allow an attacker to crash systems by sending specially crafted transmit release-report data, researchers...
Linux Kernel Patch CVE-2026-43191 Fixes AMD DCN35 TMDS PHY PLL Atomic Mode Hang
A newly published Linux kernel vulnerability, CVE-2026-43191, exposes a critical flaw in AMD’s display driver that can cause an unrecoverable system hang under specific conditions involving TMDS...
CVE-2026-43116: Linux Kernel netfilter ctnetlink Expectation Locking Vulnerability Fixed
Linux kernel developers have pushed a fix for a newly disclosed vulnerability in the netfilter conntrack module that could enable local attackers to gain elevated privileges or crash systems. The...
Patch WSL2, Linux VMs Now: Critical XFS Kernel Bug Enables Local Attacks
A newly disclosed Linux kernel vulnerability, CVE-2026-43153, targets the widely used XFS filesystem and demands immediate attention from system administrators—even those primarily managing Windows...
Linux Kernel Bug CVE-2026-43161 Hard-Locks Hosts via Intel VT-d ATS Flaw
A newly published vulnerability tracked as CVE-2026-43161 exposes a serious denial-of-service risk for Linux systems using Intel VT-d and PCIe passthrough. The flaw, detailed by the National...
CISA Flags PAN-OS Root RCE Flaw CVE-2026-0300 in User-ID Portal as Actively Exploited
Palo Alto Networks firewall administrators face an urgent patching deadline after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in PAN-OS, tracked as...
CVE-2026-0936: ABB PVI credential leak risks OT network takeover
On May 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) republished an advisory from ABB detailing a medium-severity information-disclosure vulnerability in the company’s...
CVE-2026-21661 DLL hijack in CEM AC2000 v10.6–12.0 raises privilege to SYSTEM on Windows.
CISA republished a security advisory on May 5, 2026, amplifying a warning from Johnson Controls about a high-severity DLL hijacking vulnerability in its CEM AC2000 access control system. Tracked as...
PCM600 Zip Slip Path Traversal Flaw Prompts CISA Warning for OT Engineering Workstations
CISA has republished a Hitachi Energy advisory detailing a critical path traversal vulnerability in the PCM600 configuration tool, a mainstay for protection and control engineers in electric utility...
CISA warns ABB B&R Automation Runtime DoS flaw CVE-2025-11044 risks OT shutdowns
On May 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) republished an advisory originally issued by ABB, drawing fresh attention to a critical denial-of-service (DoS)...