Waf
The latest Waf coverage — news, analysis, and updates from the WindowsNews.AI desk.
Dec 5 Azure Front Door bug triggered multi-provider 500 errors across LinkedIn, Zoom
On the morning of December 5, 2025, a significant disruption rippled across the global internet, affecting numerous high-traffic services and highlighting critical vulnerabilities in modern edge...
CISA Flags Active Exploitation of Critical DELMIA Apriso RCE Vulnerability
CISA has added CVE-2025-5086, a critical deserialization of untrusted data vulnerability in Dassault Systèmes’ DELMIA Apriso, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence...
Siemens Confirms No Patch for IEM-OS Denial‑of‑Service Flaw, Orders Migration to IEM‑V
Siemens Industrial Edge Management OS (IEM‑OS) is vulnerable to a remotely exploitable denial‑of‑service condition, and the manufacturer has confirmed it will not issue a patch. Instead, all...
Windows HTTP.sys Out-of-Bounds Read Enables Remote DoS — Patch Urgently
A newly referenced vulnerability in the Windows HTTP protocol stack exposes internet-facing servers to remote denial-of-service attacks, forcing administrators to take immediate action even as public...
Unauthenticated RCE Exploits Hit On-Prem SharePoint — Patch, Rotate Keys, and Hunt Now
Microsoft’s on-premises SharePoint servers are under active attack from a chain of vulnerabilities that grant unauthenticated attackers remote code execution (RCE). The exploit combines an...
IIS Under Fire: 2025 Patch Avalanche, ViewState RCE, and Windows Server 2025 Pitfalls
Microsoft’s Internet Information Services (IIS) has once again taken center stage in the cybersecurity spotlight. Throughout 2025, a relentless wave of security patches, newly disclosed attack...
Microsoft Patches Dynamics 365 On-Prem Flaw CVE-2025-53728 That Exposes Sensitive Data
Microsoft has released a security update to fix an information disclosure vulnerability in Dynamics 365 on-premises versions, tracked as CVE-2025-53728. The flaw, classified as allowing an...
Critical SQL Server Patches Land, but CVE Confusion Causes Headaches for Admins
Microsoft’s July 2025 Patch Tuesday brought a cluster of security updates for SQL Server that fix critical vulnerabilities, including a heap-based buffer overflow leading to remote code execution,...
SharePoint 'ToolShell' Zero-Day Exploited: Critical RCE Patched Amid Active Attacks
Microsoft has released an emergency security update to patch a critical remote code execution (RCE) vulnerability in SharePoint Server that has been actively exploited in the wild. Tracked as...
New XSS Vulnerability in Dynamics 365 On-Premises Allows Spoofing Attacks – Patch Now
Microsoft has assigned CVE-2025-49745 to a cross‑site scripting (XSS) vulnerability affecting on‑premises deployments of Dynamics 365, warning that improper input neutralization during web page...
Immediate Patch Needed: CVE-2025-49758 SQL Injection Allows SQL Server Privilege Escalation
Microsoft has released critical security updates for all supported versions of SQL Server to address CVE-2025-49758, a severe SQL injection vulnerability that could allow an authenticated attacker to...
Sante PACS Server Flaws Chain Path Traversal, Double-Free, XSS—Patch Urged as Advisories Clash
Security researchers have disclosed a quartet of vulnerabilities in Sante PACS Server, a medical imaging platform deployed across clinics and hospitals, that combine to create a near-critical risk of...