Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Flags Kernel-Mode HTTP.sys Bug: Prepare Your Windows Servers Now
Microsoft’s security team has posted a new advisory for a high-severity elevation-of-privilege flaw in the Windows HTTP.sys driver. The vulnerability, tracked as CVE-2026-20929, could let an...
CVE-2026-20874: Critical WMSvc Elevation of Privilege Vulnerability Patched in January 2026 Update
Microsoft has addressed a critical elevation of privilege vulnerability in Windows Management Services (WMSvc) tracked as CVE-2026-20874, which was patched in the company's January 2026 security...
CVE-2026-20873: Critical Windows Management Services EoP Vulnerability Patched
Microsoft has addressed a significant security vulnerability in its January 2026 Patch Tuesday updates, with CVE-2026-20873 representing an Elevation of Privilege (EoP) flaw affecting Windows...
NTLM Hash Leak via Windows Explorer Fixed in New CVE-2026-20872 Patch
Microsoft has identified a significant security vulnerability in Windows Shell and File Explorer components that could expose users to credential theft attacks. Designated as CVE-2026-20872, this...
CVE-2026-20871: Microsoft Patches Critical DWM Privilege Escalation Flaw in Windows
Microsoft's January 2026 Patch Tuesday security updates addressed a significant elevation-of-privilege vulnerability in the Desktop Window Manager (DWM) component of Windows, tracked as...
CVE-2026-20871: Critical DWM Vulnerability Threatens Windows Security
Microsoft has disclosed a significant security vulnerability in the Desktop Window Manager (DWM) component of Windows, tracked as CVE-2026-20871, which presents a high-severity elevation-of-privilege...
Microsoft Warns of High-Confidence Win32k Bug That Hands Attackers SYSTEM Access—Patch Now
Microsoft on Tuesday posted CVE-2026-20870 to its Security Update Guide, a local privilege escalation vulnerability in the Windows Win32 kernel subsystem that the company has confirmed with “high...
New Windows Management Services EoP Flaw (CVE-2026-20866) Risks Full System Takeover — Patch Immediately
Microsoft has acknowledged a new local elevation-of-privilege vulnerability in Windows Management Services, tracked as CVE-2026-20866, that could allow an attacker to escalate from a standard user...
Patch Now: CVE-2026-20861 in Windows Management Services Can Escalate to SYSTEM Privileges
Microsoft’s first Patch Tuesday of 2026 dropped a fix for a vulnerability that hands attackers a direct path to total system control—if they already have a toehold on your machine....
Critical Windows Kernel Patch Closes Door to Privilege Escalation Attacks
Microsoft this week began rolling out a security update that fixes a dangerous flaw in the Windows kernel, warning that attackers who already have a foothold on a system could use it to seize total...
Microsoft Patches Critical Windows COM Flaw That Allows Remote Code Execution via Malicious Documents
Microsoft has shipped a security update to stamp out a critical vulnerability in a widely used Windows component, one that could allow attackers to hijack computers just by getting users to open a...
Microsoft Flags New Windows RCE Bug in Inbox COM Objects — Apply Patches Now
Microsoft has published a security advisory for a newly discovered remote code execution vulnerability in Windows that targets built-in Component Object Model (COM) components, designated...