Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Windows Now: CVE-2026-42968 Telephony Service Leaks Credentials
Microsoft released a security update on June 9, 2026 to address CVE-2026-42968, an information disclosure vulnerability in the Windows Telephony Service rated as Important. The patch arrives as part...
CVE-2026-42911: Windows AFD.sys Privilege Escalation Flaw Patched in June 2026 Update
Microsoft released a patch on June 9, 2026, for CVE-2026-42911, an Important-rated elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). The flaw could...
CVE-2026-42913: High-Severity RDP Client RCE Flaw Hits Windows 11 and Server — What You Must Do Now
Microsoft on June 9, 2026, disclosed CVE-2026-42913, a critical remote code execution vulnerability in the Remote Desktop Protocol (RDP) client, affecting Windows 11, Windows Server 2022, and Windows...
Windows Kernel Flaw CVE-2026-42916: Patch Now to Block Full SYSTEM Takeover
Microsoft’s June 2026 Patch Tuesday delivered a fix for CVE-2026-42916, a high-severity elevation-of-privilege vulnerability lurking in the Windows NT OS Kernel. Disclosed on June 9, 2026, this...
CVE-2026-42909: Patch Windows RDP Client Now, Block Outbound RDP
Microsoft dropped a potentially disruptive remote code execution advisory this Patch Tuesday that should stop every Windows admin in their tracks. CVE-2026-42909, rated Important, is a bug in the...
CVE-2026-42980: Patch Critical NT Kernel EoP Bug Now (CVSS 7.8)
Microsoft dropped its June 2026 Patch Tuesday updates on June 9, addressing a total of 67 vulnerabilities across the Windows ecosystem. Among them, CVE-2026-42980 stands out as a local...
ProjFS bug CVE-2026-42837 lets local attackers escalate to SYSTEM via kernel buffer over-read
Microsoft's June 2026 security update addresses CVE-2026-42837, a local privilege escalation vulnerability in the Windows Projected File System (ProjFS) filter driver. An attacker who successfully...
CVE-2026-42836: Windows Elevation of Privilege via Race Condition in Function Discovery Service
On June 9, 2026, Microsoft released its monthly Patch Tuesday updates, tackling CVE-2026-42836—an elevation-of-privilege vulnerability in the Windows Function Discovery Service. The flaw, rated...
Microsoft PC Manager Flaw Lets Local Attackers Gain SYSTEM Privileges
Microsoft has confirmed a high-severity security flaw in its PC Manager utility that could allow a local attacker to seize full control of a Windows system. Tracked as CVE-2026-50512, the...
Microsoft Patch Tuesday Fixes CVE-2026-50511 PC Manager Privilege Escalation Flaw
Microsoft disclosed a new elevation-of-privilege vulnerability in its PC Manager utility on June 9, 2026. Tracked as CVE-2026-50511, the flaw stems from improper link handling before file access,...
CVE-2026-50507: Microsoft Reveals BitLocker Bypass That Lets Attackers With Physical Access Decrypt Drives
Microsoft published CVE-2026-50507 on June 9, 2026, as part of its monthly Patch Tuesday release. The vulnerability is classified as a Windows BitLocker security feature bypass, allowing an attacker...
CVE-2026-49160: Critical HTTP.sys DoS Flaw Patched in June 2026 Patch Tuesday – Update Now
Microsoft rolled out its June 2026 Patch Tuesday updates with a critical fix for a denial-of-service vulnerability in Windows HTTP Protocol Stack (HTTP.sys), tracked as CVE-2026-49160. The flaw,...