Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows SSTP Vulnerability Exposes VPN Gateways to RCE Attacks: What IT Must Do Now
Microsoft dropped a security advisory on July 14, 2026, that every Windows administrator should read: CVE-2026-50694, a remote code execution vulnerability in the Secure Socket Tunneling Protocol...
Microsoft’s New ASP.NET Core DoS Warning Is Light on Details—Here’s Your Prep Checklist
On July 14, 2026, Microsoft published CVE-2026-56170, a new denial-of-service vulnerability in ASP.NET Core. The initial advisory, however, contains a critical gap: it lists no affected product...
Microsoft Fixes Network-Elevation Flaw in Windows Admin Center – Patch Now
Microsoft has patched a high-severity vulnerability in Windows Admin Center that could allow an attacker with low-level access to seize control of an entire managed network. The flaw, tracked as...
Microsoft Ships AD FS Fix, But Automatic Remediation Is Months Away — Here’s How to Secure Your Keys Now
Microsoft shipped a security fix on July 14, 2026, for a dangerous elevation-of-privilege flaw in Active Directory Federation Services (AD FS) that attackers are already exploiting. But any...
High-Severity CVE-2026-55948: Excel Workbook Flaw Demands Quick Patch
Microsoft on July 14, 2026 detailed CVE-2026-55948, a use-after-free vulnerability in Microsoft Office Excel that carries a CVSS 3.1 score of 7.8. An attacker who crafts a malicious workbook can...
Excel Patch for July 2026 Closes Remote Code Execution Hole Exploited via Malicious Files
On July 14, 2026, Microsoft released a security update for Microsoft Excel that fixes a vulnerability allowing attackers to run arbitrary code on a victim’s machine simply by having them open a...
CVE-2026-54988: Microsoft's Excel Update Fixes Data Leak and Crash Flaw
On July 14, Microsoft released a security update for Microsoft Office Excel that patches a memory-read vulnerability rated Medium severity. Despite the modest score, the flaw can crash Excel or cause...
Microsoft Deploys Fix for Excel Heap Overflow That Can Crash Apps and Expose Data
Microsoft shipped a security update on July 14, 2026, that plugs a heap-based buffer overflow in Excel capable of leaking information and abruptly terminating the application when a user opens a...
Microsoft Patches Excel Flaw That Turns a Simple Spreadsheet into a Backdoor
Microsoft issued a security fix on July 14, 2026, for a flaw in Excel that can give attackers full control of a PC when a victim opens a poisoned spreadsheet. The vulnerability, tracked as...
Microsoft Patches SharePoint Spoofing Flaw That Can Leak Data Without a Click
Microsoft’s July 14, 2026 security update fixes a vulnerability in on-premises SharePoint Server that lets already-authenticated attackers spoof content and siphon sensitive documents — no...
Visual Studio Code 1.128.1 Fixes Command Injection Flaw; Update Now to Block Code Execution Attacks
Microsoft released Visual Studio Code version 1.128.1 on July 14, 2026, patching a high-severity command-injection vulnerability tracked as CVE-2026-50520. The flaw allows an attacker to execute...
CVE-2026-55144: Windows Crypto Bug Exposes Confidential Data to Local Attackers – July 2026 Fix Urged
Microsoft’s July 14, 2026 security update seals a dangerous hole in Windows’ core cryptographic engine that could let intruders with minimal access pry open protected data. CVE-2026-55144, rated...