Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
SharePoint Server faces critical 8.8-severity spoofing flaw CVE-2025-21393 before April patch
Critical CVE-2025-21393 Vulnerability Discovered in Microsoft SharePoint Server Microsoft has issued a critical security advisory regarding CVE-2025-21393, a newly discovered spoofing vulnerability...
UPnP memory corruption bug CVE-2025-21389 lets attackers crash Windows via port 1900
A newly discovered critical vulnerability (CVE-2025-21389) in Windows' Universal Plug and Play (UPnP) host service (upnphost.dll) exposes systems to denial-of-service (DoS) attacks. This security...
Firmware flaw CVE-2024-7344 enables Secure Boot bypass on Howyar industrial PCs.
A newly discovered vulnerability, tracked as CVE-2024-7344, has been identified in certain Howyar Taiwan devices, posing a significant risk to Secure Boot implementations. This firmware-level flaw...
Windows Zero-Day Alert: CVE-2025-21219 Exploits MapUrlToZone for Privilege Escalation
CVE-2025-21219: Understanding the New Windows Security Vulnerability A newly discovered security vulnerability, tracked as CVE-2025-21219, has raised concerns among Windows users and IT...
Patch Now: CVE-2025-21382 Exploited in Windows Privilege Attacks
Microsoft Windows users are facing a new security threat with the discovery of CVE-2025-21382, a critical elevation of privilege vulnerability affecting multiple Windows versions. This zero-day flaw,...
Critical Microsoft Access RCE Bug Puts Legacy Systems at Risk
A newly discovered vulnerability in Microsoft Access, tracked as CVE-2025-21366, has been classified as critical due to its potential for remote code execution (RCE). This security flaw affects...
CVE-2025-21365: Critical Microsoft Office RCE Vulnerability Threatens Enterprise Security
CVE-2025-21365: New Microsoft Office RCE Vulnerability Risks Exploitation A newly discovered remote code execution (RCE) vulnerability in Microsoft Office, tracked as CVE-2025-21365, has raised...
CVE-2025-21364: Critical Excel Vulnerability Threatens Data Security - What You Need to Know
Microsoft Excel users face a new security threat with the discovery of CVE-2025-21364, a critical vulnerability that could allow attackers to execute malicious code through specially crafted...
Microsoft Issues Urgent Patch for Critical Word RCE Flaw CVE-2025-21363
A newly discovered critical vulnerability in Microsoft Word (CVE-2025-21363) has security experts urging immediate action. This remote code execution flaw could allow attackers to take complete...
CVE-2025-21362: Critical Excel Vulnerability Puts Users at Risk of Remote Code Execution
CVE-2025-21362: Major Excel Vulnerability Exposes Users to RCE Risks A newly discovered vulnerability in Microsoft Excel, tracked as CVE-2025-21362, has raised significant concerns among...
CVE-2025-21357: Critical Remote Code Execution Vulnerability Discovered in Microsoft Outlook
CVE-2025-21357: Critical RCE Vulnerability in Microsoft Outlook Microsoft has disclosed a critical security vulnerability (CVE-2025-21357) affecting all supported versions of Microsoft Outlook that...
Microsoft Visio Zero-Day RCE Exploited in Wild—Patch Pending, Immediate Action Urged
Microsoft has issued a critical security alert regarding a newly discovered Remote Code Execution (RCE) vulnerability in Microsoft Office Visio, tracked as CVE-2025-21356. This zero-day flaw allows...