Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
July 2026 Windows Update Closes USB Print Driver Flaw That Could Hand Attackers System Control
Microsoft's July 2026 security update fixes a vulnerability in the Windows USB print driver that could allow an attacker already on a machine to escalate their privileges and take full control of the...
Windows July 2026 Patches Fix SMB Memory Leak That Could Leak Secrets
On July 14, 2026, Microsoft patched a vulnerability in the Windows Server Message Block (SMB) protocol that allows a low-privilege attacker to extract information from uninitialized memory. Tracked...
Microsoft Patches Spaceport.sys Privilege Escalation Flaw—All Windows Users Should Update Now
Microsoft fixed a local privilege escalation vulnerability in the Windows Spaceport.sys driver on July 14, 2026, as part of its monthly Patch Tuesday updates. The flaw, tracked as CVE-2026-50333,...
Microsoft's July Patches Fix Windows Kernel Vulnerability That Leaks Sensitive Data to Local Attackers
Microsoft shipped security updates on July 14, 2026, that close a kernel information-disclosure hole tracked as CVE-2026-50294. The flaw lets an unprivileged local attacker read sensitive kernel...
That Windows Server Bug in July’s 570-Patch Update Can Give Attackers Full Control — Here’s What to Do
Microsoft fixed a high-severity privilege-escalation vulnerability on July 14 that lurks inside nearly every supported version of Windows Server and also affects modern Windows client releases. The...
Microsoft Patches NTFS Flaw That Could Allow Code Execution via Malicious Files — All Windows Versions Affected
Microsoft has patched a serious vulnerability in the Windows NTFS file system that could allow attackers to execute arbitrary code after a user opens a specially crafted file. The flaw, tracked as...
Windows LSASS Attack Can Force Server Reboots—July Patch Blocks It
Microsoft’s July 2026 security updates close a network-based denial-of-service vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) that allowed an authenticated attacker...
CVE-2026-49800: Why You Need the July 2026 Windows Updates to Stop a WPAD Attack
On July 14, 2026, Microsoft's monthly security release addressed CVE-2026-49800, a high-severity elevation-of-privilege vulnerability in Windows' Web Proxy Auto-Discovery Protocol (WPAD). Clocking in...
Patch Now: Microsoft Fixes 9.3-Score Windows Kernel Flaw That Needs No Admin to Exploit
On July 14, 2026, Microsoft pushed out a security fix that every Windows user should install immediately. The star of the July Patch Tuesday lineup is CVE-2026-49798, a use-after-free flaw in the...
CVE-2026-49797: Windows NTFS Patch Fixes Code Execution Flaw, But It’s Not a Network Threat
On July 14, 2026, Microsoft rolled out security updates fixing a heap-based buffer overflow vulnerability in Windows NTFS — the file system that underpins every modern Windows client and server...
Microsoft Ships Fix for Windows Kernel Privilege Escalation That's 'More Likely' to Be Exploited
On July 14, 2026, Microsoft released its monthly Patch Tuesday updates, and one bulletin stands out: CVE-2026-49795, a local elevation-of-privilege bug in the Windows Kernel. The company rates it...
Windows GDI+ Heap Overflow Threatens Millions of PCs – Patch Now, Microsoft Warns
On July 14, 2026, Microsoft’s latest Patch Tuesday release fixed a heap-based buffer overflow in the Windows Graphics Device Interface Plus (GDI+), a core component responsible for rendering images...