Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-42982: Microsoft Reveals Windows Secure Kernel Flaw, But Leaves Users Guessing on Fixes
On July 14, 2026, Microsoft published a new vulnerability—CVE-2026-42982—affecting the Windows Secure Kernel. The advisory labels it as an Elevation of Privilege flaw, but it’s missing the most...
CVE-2026-48561: Microsoft Warns of Copilot RCE Flaw Without Providing Fix Details
{ "title": "CVE-2026-48561: Microsoft Warns of Copilot RCE Flaw Without Providing Fix Details", "content": "On July 14, 2026, at 7:00 a.m. Pacific time, Microsoft published a new vulnerability...
ABB's Advant Master Update Snafu Hides a Local DLL Vulnerability—Here's What to Check
ABB has disclosed a local code-execution flaw in its Advant Master industrial control engineering software, but what makes CVE-2025-13162 unusually sticky isn't the vulnerability itself—it's the...
ABB Ships Critical Patch for Edgenius Root Escalation Bug—What Windows IT Teams Need to Know
ABB has shipped Edgenius version 3.2.4.1 to fix CVE-2026-31431, a high-severity Linux kernel vulnerability that can hand root privileges to an attacker already operating with a restricted local...
Rockwell Adapter's Perfect 10 Vulnerability Puts Windows Networks on High Alert
Rockwell Automation's 1715-AENTR EtherNet/IP adapter has a flaw that lets attackers take full control without a password, and it carries a perfect CVSS score of 10. The bug, designated...
Critical 9.9-Severity Vulnerability in ABB T-MAC Plus Requires Immediate Patching
Operators of chemical, petroleum, and hydrogen terminals face a serious cybersecurity threat after ABB confirmed that a critical flaw in its T-MAC Plus terminal management system could hand...
CISA: Disable These 3 Router Features Now to Block Russian State Hackers
Russian Federal Security Service (FSB) operatives are actively scanning the Internet for poorly configured routers, exploiting a decades-old protocol to steal full device configurations, according to...
18-Year-Old Cisco Bug Now Under Active Attack—CISA Demands Immediate Router Replacement
On July 13, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical-but-ancient vulnerability in Cisco routers to its Known Exploited Vulnerabilities (KEV) catalog,...
Microsoft Discloses Edge RCE Vulnerability, Omits Version and Attack Details
Microsoft published a security advisory for CVE-2026-58281, a remote code execution vulnerability in the Chromium-based Edge browser, but omitted critical information including which versions are...
Chrome 150 Patches Tint Sandbox Escape—Why Windows Users Need to Update Now
Google has released Chrome 150.0.7871.46 for Windows, Mac, and Linux, and it’s not just another routine update. Tucked inside the change log is a fix for CVE-2026-14392, a high‑severity bug that...
Google Rushes Out Chrome 150 Emergency Patch for Windows—Here’s Why You Need It Now
Google shipped an unscheduled Chrome security update on Tuesday, pushing version 150.0.7871.46 to Windows users after discovering a vulnerability that attackers are already exploiting in the wild....
Urgent Chrome Update: Patch CVE-2026-14393 Immediately to Avoid Potential Exploits
Google pushed out Chrome 150.0.7871.46 this week, a no-frills security update that tackles one high-stakes vulnerability: CVE-2026-14393. If you haven’t already relaunched your browser, you’re...