Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows Narrator Braille DLL flaw lets attackers gain SYSTEM access
Microsoft has published CVE-2026-48565, an Important-rated elevation-of-privilege vulnerability in Windows Narrator’s Braille support. A local, authenticated attacker who successfully exploits this...
Microsoft’s Latest Boot Manager Fix Is a Warning Shot for Your PC’s Startup Security
Microsoft shipped a security update in June 2026 to close a loophole in Windows Boot Manager, a component that decides what runs before your operating system fully loads. The fix, tracked as...
CVE-2026-45608: Microsoft Patches Windows DHCP Client Information Disclosure Flaw – June 2026 Patch Tuesday
Microsoft's June 2026 Patch Tuesday release, published on June 9, contained a fix for CVE-2026-45608, an information disclosure vulnerability in the Windows DHCP Client service. The bug, listed in...
June 2026 Patch Tuesday: Fix This DWM Bug That Turns Low-Level Access Into SYSTEM Control
Microsoft’s June 9, 2026 Patch Tuesday rollout plugged CVE-2026-45637, an Important-rated elevation-of-privilege (EoP) vulnerability inside the Desktop Window Manager (DWM) core library. Assigned a...
Critical AFD.sys Flaw Grants SYSTEM Access—Patch CVE-2026-45603 Now
Microsoft has released a security update to address a critical elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2026-45603. The...
CVE-2026-45638: Windows WinSock AFD Driver Local Privilege Escalation Flaw Patched
Microsoft patched a critical local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) on June 9, 2026, as part of its monthly Patch Tuesday updates....
Patch Now: CVE-2026-45635 UPnP RCE Exploited in the Wild
Microsoft’s June 2026 Patch Tuesday delivered a critical fix for CVE-2026-45635, an Important-rated remote code execution (RCE) vulnerability in the Windows Universal Plug and Play (UPnP) Device...
Patch CVE-2026-45596 now: Windows AFD bug grants SYSTEM access to all users
Microsoft kicked off its June 2026 Patch Tuesday with a critical fix for CVE-2026-45596, a local elevation of privilege vulnerability lurking in the Windows Ancillary Function Driver for WinSock,...
CVE-2026-45636: Patch Windows NTFS VHD Flaw Now Despite Misleading "Remote" Label
Microsoft dropped its June 2026 Patch Tuesday update, and among the fixes is CVE-2026-45636, a vulnerability that underscores why security classifications can be misleading. The flaw, rated...
Patch Now: Critical CVE-2026-45598 AFD.sys Bug Gives Hackers SYSTEM Access
Microsoft's June 2026 Patch Tuesday has arrived with a crucial fix for CVE-2026-45598, an Important-rated elevation-of-privilege vulnerability residing in the Windows Ancillary Function Driver for...
Microsoft Urges Patching of CVE-2026-45601: WinSock AFD Driver Exploit Leads to SYSTEM Access
Microsoft’s June 2026 Patch Tuesday closed a dangerous elevation-of-privilege hole in the Windows Ancillary Function Driver for WinSock (AFD). Tracked as CVE-2026-45601, the flaw grants a locally...
Windows UPnP Device Host RCE (CVE-2026-45599) Patched in June 2026 Update
Microsoft has pushed out a security update for a high-severity remote code execution vulnerability in the Windows UPnP Device Host service. Tracked as CVE-2026-45599, the flaw carries an 8.1 CVSS...