Windows Security News

Security news specific to Microsoft Windows: vulnerabilities, exploitation and patches affecting Windows systems.

Windows is the most widely deployed desktop and enterprise operating system, and a constant target for both criminal and state-linked attackers. Windows-specific CVEs, in-the-wild exploitation, and Microsoft's Patch Tuesday and out-of-band fixes show up here. Expect heavy overlap with the ransomware and exploit feeds: Windows endpoints remain the most common initial-access target.

Recent Windows items

File Notification Attacks Let Hackers Track Keystrokes and Website Visits on Linux, Windows and macOS https://gbhackers.com/file-notification-attacks/
@PentestingNews · Sep 29, 2026
Researchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams https://gbhackers.com/windows-rat-espionage/
@PentestingNews · Sep 29, 2026
CVE-2026-92142 Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI r…
@cveNotify · Sep 29, 2026
CVE-2020-37254 Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious exe…
@cveNotify · Sep 29, 2026
rPlayAI/rPlayHub: iPhone Mirroring for macOS and Linux — scrcpy for iOS and a cross-platform Device Hub clone. Mirror and control an iPhone (iOS 27+); Raspberry Pi and Windows next. Part of rPlay. htt…
@malwr · Sep 29, 2026
CVE-2026-91006 Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix…
@cveNotify · Sep 29, 2026
CVE-2026-63448 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-complete…
@cveNotify · Sep 28, 2026
CVE-2026-57224 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/ dhcp.rs c…
@cveNotify · Sep 28, 2026
CVE-2026-62744 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. 🎖
@cveNotify · Sep 28, 2026
CVE-2026-93537 A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can caus…
@cveNotify · Sep 28, 2026
CVE-2026-81886 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64…
@cveNotify · Sep 28, 2026
CVE-2026-7514 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role p…
@cveNotify · Sep 28, 2026
CVE-2026-19444 A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the containe…
@cveNotify · Sep 28, 2026
SmartLoader delivers additional payloads while gathering system information, establishing persistence, and maintaining C2 communication on compromised Windows systems. 👉 Explore how to detect and redu…
@anyrun_app · Sep 28, 2026
CVE-2026-91006 Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix…
@cveNotify · Sep 28, 2026
CVE-2026-12268 ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. 🎖
@cveNotify · Sep 28, 2026
CVE-2026-12267 ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution. 🎖
@cveNotify · Sep 28, 2026
CVE-2026-76578 A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthentic…
@cveNotify · Sep 28, 2026
CVE-2026-13097 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for e…
@cveNotify · Sep 28, 2026
CVE-2026-11861 A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, includi…
@cveNotify · Sep 28, 2026
CVE-2026-19550 A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authentica…
@cveNotify · Sep 28, 2026
CVE-2026-18948 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote a…
@cveNotify · Sep 28, 2026
CVE-2026-97561 In the Linux kernel, the following vulnerability has been resolved: smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid When the administrator mounts with forceuid or forc…
@cveNotify · Sep 28, 2026
CVE-2026-97554 In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() cifs_posix_to_fattr() ignores the return value o…
@cveNotify · Sep 28, 2026
CVE-2026-96280 The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while…
@cveNotify · Sep 27, 2026
CVE-2026-101063 Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry…
@cveNotify · Sep 27, 2026
CVE-2026-96279 A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of…
@cveNotify · Sep 27, 2026
CVE-2026-96279 A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of…
@cveNotify · Sep 27, 2026
CVE-2026-101043 pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's p…
@cveNotify · Sep 27, 2026
CVE-2026-100741 Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run…
@cveNotify · Sep 27, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.