Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-45588 Secure Boot Bypass: Deploy June 2026 OS Update and UEFI Revocation List
A critical Secure Boot bypass vulnerability, assigned CVE-2026-45588, landed on Microsoft’s radar with the release of the June 2026 Patch Tuesday updates. Published on June 9, the advisory ranks...
CVE-2026-45634: Windows DHCP Client Vulnerability Exposes Sensitive Data, Patch Released
Microsoft’s June 2026 Patch Tuesday brought a grim reminder of how legacy network protocols continue to haunt enterprise security. Among the 70-plus vulnerabilities addressed this month,...
Windows June 2026 Update Closes UxTheme Loop: A Visual Engine Crash That Local Attackers Can Trigger
On June 9, 2026, Microsoft disclosed and patched a denial-of-service flaw in the Windows UxTheme Library, the system component responsible for drawing themed controls and window chrome....
Patch Your Windows Now: Critical Bluetooth Driver EoP Bug CVE-2026-45640
Microsoft has acknowledged a new elevation-of-privilege (EoP) vulnerability, tracked as CVE-2026-45640, affecting the Windows Bluetooth Port Driver. Disclosed through the Microsoft Security Response...
Windows PCA Bug Lets Local Attackers Seize SYSTEM Rights—Patch Now
Microsoft has disclosed a local elevation-of-privilege (EoP) vulnerability in the Windows Program Compatibility Assistant (PCA) Service, tracked as CVE-2026-45487. The advisory, released on June 9,...
Claude Fable 5 Routes Windows AI Risks to Opus 4.8 for Safety
Anthropic shook the enterprise AI landscape on June 9, 2026, with the release of Claude Fable 5, its first Mythos-class model now broadly available through the Claude API. The launch introduces an...
CVE-2026-44821: Microsoft Office Info Leak Patched on Windows, Mac Users Must Wait
Microsoft's June 2026 Patch Tuesday brought a fix for CVE-2026-44821, an information disclosure vulnerability in Microsoft Office rated Important. The flaw, caused by an out-of-bounds read, could...
Windows Device Health Attestation Flaw (CVE-2026-33828) Grants Attackers SYSTEM-Level Access
Microsoft’s June 2026 Patch Tuesday rollout on June 9 delivered a jolt to Windows administrators with the disclosure of CVE-2026-33828, a critical elevation-of-privilege vulnerability in the Device...
CVE-2026-40404: Critical Windows UDFS Elevation of Privilege Flaw Patched – What You Need to Know
Microsoft released a patch for CVE-2026-40404 on June 9, 2026, closing a high-severity elevation-of-privilege vulnerability in the Windows Universal Disk Format (UDFS) file system driver. The flaw...
Critical UDFS Elevation-of-Privilege Flaw (CVE-2026-40409) Patched in June 2026 Windows Update
Microsoft pushed out a security update on June 9, 2026 that fixes CVE-2026-40409, an elevation-of-privilege vulnerability in the Windows Universal Disk Format (UDF) file system driver. The flaw,...
Windows 11 LTSC Hotpatch Paused: Why Microsoft Just Forced a Reboot to Patch a Dangerous BitLocker Bug
On June 9, 2026, Microsoft broke its silence—and its routine. Instead of delivering the usual reboot-free hotpatch for Windows 11 Enterprise LTSC 2024, the company pushed a full baseline update...
Decode Windows 11 Pro Security Alerts: When to Act or Ignore
Windows 11 Pro floods users with security alerts—from the Windows Security app, Microsoft Defender Antivirus, SmartScreen, and Smart App Control. Each one pushes a specific action: update,...