Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,726Advisories collected
2,720Published or updated in 30 days
2,115Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,726 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Palo Alto Networks Security AdvisoriesCVE-2026-0250
HighCVSS 7.7

CVE-2026-0250: GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of req...

Affected productsGlobalProtect App, GlobalProtect UWP App, GlobalProtect App 6.3, GlobalProtect App 6.2
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h9 on Windows, >= 6.3.3-h9 on macOS, >= 6.3.5 on Android, >= 6.3.5 on ChromeOS, >= 6.3.3-h15 on Linux (ETA: 09/17), GlobalProtect App 6.2 >= 6.2.8-h10 on Windows, >= 6.2.8-h10 on macOS, GlobalProtect App 6.1 >= 6.1.14 on Android, >= 6.1.14 on ChromeOS, GlobalProtect App 6.0 >= 6.0.15 on Linux (ETA: 10/29), >= 6.0.13 on Windows, >= 6.0.13 on macOS, >= 6.0.15 on Android (ETA: 10/29), >= 6.0.15 on ChromeOS (ETA: 10/29)
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h8 Upgrade to 6.3.3-h9 (6.3.3-999) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h9 Upgrade to 6.2.8-h10 (...

Palo Alto Networks Security AdvisoriesCVE-2026-0299
HighCVSS 8.5

CVE-2026-0299: GlobalProtect App: Local Privilege Escalation Vulnerabilities

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with ad...

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.2, GlobalProtect App 6.0
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h14 (6.3.3-1121) on macOS, >= 6.3.3-h14 (6.3.3-1121) on Windows, GlobalProtect App 6.2 None on Linux, >= 6.2.8-h13 (6.2.8-1045) on macOS, >= 6.2.8-h13 (6.2.8-1045) on Windows, GlobalProtect App 6.0 >= 6.0.15 on Linux (ETA: 10/29), >= 6.0.15 on macOS (ETA: 10/29), >= 6.0.15 on Windows (ETA: 10/29), GlobalProtect App All on iOS, All on Android, All on Chrome OS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. Global...

Palo Alto Networks Security AdvisoriesCVE-2026-0298
HighCVSS 7.7

CVE-2026-0298: GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an ...

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.2, GlobalProtect App 6.0
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h14 (6.3.3-1121) on Windows, GlobalProtect App 6.2 >= 6.2.8-h13 (6.2.8-1045) on Windows, GlobalProtect App 6.0 >= 6.0.15 on Windows (ETA: 10/29), GlobalProtect App All on Linux, All on macOS, All on Android, All on Chrome OS, All on iOS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h...

Palo Alto Networks Security AdvisoriesCVE-2026-0296
HighCVSS 7.4

CVE-2026-0296: GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS...

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.2, GlobalProtect App 6.0
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h14 (6.3.3-1121) on macOS, >= 6.3.3-h14 (6.3.3-1121) on Windows, GlobalProtect App 6.2 None on Linux, >= 6.2.8-h13 (6.2.8-1045) on macOS, >= 6.2.8-h13 (6.2.8-1045) on Windows, GlobalProtect App 6.0 >= 6.0.15 on Linux (ETA: 10/29), >= 6.0.15 on macOS (ETA: 10/29), >= 6.0.15 on Windows (ETA: 10/29), GlobalProtect App All on iOS, All on Android, All on Chrome OS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. Global...

Palo Alto Networks Security AdvisoriesCVE-2026-0295
HighCVSS 7.2

CVE-2026-0295: GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.2, GlobalProtect App 6.0
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h14 (6.3.3-1121) on macOS, GlobalProtect App 6.2 >= 6.2.8-h13 (6.2.8-1045) on macOS, GlobalProtect App 6.0 >= 6.0.15 on macOS (ETA: 10/29), GlobalProtect App All on Linux, All on Windows, All on iOS, All on Android, All on Chrome OS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (...

Palo Alto Networks Security AdvisoriesCVE-2026-0297
HighCVSS 7.7

CVE-2026-0297: GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, an...

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.2, GlobalProtect App 6.0
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h14 on macOS, >= 6.3.3-h14 on Windows, >= 6.3.5 on iOS, >= 6.3.5 on Android, >= 6.3.5 on Chrome OS, GlobalProtect App 6.2 None on Linux, >= 6.2.8-h13 on macOS, >= 6.2.8-h13 on Windows, GlobalProtect App 6.0 >= 6.0.15 on Linux (ETA: 10/29), >= 6.0.15 on macOS (ETA: 10/29), >= 6.0.15 on Windows (ETA: 10/29), >= 6.0.15 on iOS (ETA: 10/29), >= 6.0.15 on Android (ETA: 1
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. Global...

AWS Security BulletinsCVE-2026-89332
Severity not listed

CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. W...

Microsoft Security Response CenterCVE-2026-76023
Severity not listed

Chromium CVE-2026-76023: Improper resource control in Linux Toolkit Theming

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions151.0.4129.107
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-76039
Severity not listed

Chromium CVE-2026-76039: Incorrect reference resolution in Core

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions151.0.4129.101
Vendor guidance

Release Notes

AWS Security BulletinsCVE-2026-18061
Severity not listed

CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin

Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that enhances existing JDBC drivers with AWS-specific capabilities such as Aurora fa...

AWS Security BulletinsCVE-2026-89065
Severity not listed

CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection

Bulletin ID: 2026-108-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:00 AM PDT Description: projen is an open-source tool for defining and synthesizing software project configurations as code. AWS identified two issues in projen aff...

Cisco Security Advisoriescisco-sa-hardening-iosxr-qg64NcM
CriticalPriority signal

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered v...

Vendor guidance

To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerab...

Microsoft Security Response CenterCVE-2026-81355
CriticalCVSS 7.5

Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69860
CriticalCVSS 8.8

Windows Imaging Component Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.