Windows Security News

Security news specific to Microsoft Windows — vulnerabilities, exploitation and patches affecting Windows systems.

As the most widely deployed desktop and enterprise operating system, Windows is a constant target for both criminal and state-linked attackers. This feed tracks Windows-specific CVEs, in-the-wild exploitation and Microsoft's Patch Tuesday and out-of-band fixes as they are reported. It overlaps heavily with the ransomware and exploit feeds, since Windows endpoints remain the most common initial-access target.

Recent Windows items

CVE-2026-70338Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62908Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.🎖@cveNoti…
@cveNotify · Aug 14, 2026
CVE-2026-62742Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62720Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62718Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62716Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62715Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62714Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-19768Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings mana…
@cveNotify · Aug 14, 2026
CVE-2026-63093Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the rep…
@cveNotify · Aug 14, 2026
CVE-2026-19768Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings mana…
@cveNotify · Aug 14, 2026
CVE-2026-70344Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CoolClient now uses a signed rootkit to hide at the Windows kernel level.The Mustang Panda-linked backdoor can hide its process, files, registry entries, and some C2 activity.Kaspersky found victims i…
@thehackernews · Aug 14, 2026
CVE-2026-72836FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled an…
@cveNotify · Aug 14, 2026
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkithttps://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
@PentestingNews · Aug 14, 2026
Live Chrome and Edge sessions can be hijacked without cookie replay.Researchers show how CDP can be enabled inside an already-running Windows browser, letting an attacker use its existing authenticate…
@thehackernews · Aug 14, 2026
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkithttps://ift.tt/IoMRJ3Y
@ctinow · Aug 14, 2026
New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPLhttps://ift.tt/utxqSEP
@ctinow · Aug 14, 2026
China-linked Jewelbug runs espionage and crypto fraud from the same platform.XG-Web lets operators control browsers, steal credentials and cookies, and execute commands on Windows hosts. One espionage…
@thehackernews · Aug 14, 2026
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities cataloghttps://securityaffairs.com/197110/uncategorized/u-s-cisa-adds-metabase-windows-and-cisc…
@PentestingNews · Aug 14, 2026
CVE-2026-68431In the Linux kernel, the following vulnerability has been resolved:ksmbd: validate minimum PDU size for transform requestsThe receive path applies the minimum SMB2 PDU size check only wh…
@cveNotify · Aug 13, 2026
CVE-2026-18097IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the…
@cveNotify · Aug 13, 2026
CVE-2026-18096IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-13094IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.🎖@cv…
@cveNotify · Aug 13, 2026
CVE-2026-62894Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-62889Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-62888Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-62811Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-62799Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-62797Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 13, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.