Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,726Advisories collected
2,720Published or updated in 30 days
2,115Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,726 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Palo Alto Networks Security AdvisoriesCVE-2026-0302
MediumCVSS 4.7

CVE-2026-0302: Checkov by Prisma Cloud: OS Command Injection Vulnerability

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

Affected productsCheckov by Prisma Cloud, Checkov by Prisma Cloud 3.2.0
Fixed versionsCheckov by Prisma Cloud 3.2.0 >= 3.2.502
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.501 Upgrade to 3.2.502 or later.

Microsoft Security Response CenterCVE-2026-85046
Severity not listed

Chromium: CVE-2026-85046 Type confusion in V8

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.62
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-85091
HighCVSS 7.4

zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate

Mariner

Affected productsazl3 zlib 1.3.2-1 on Azure Linux 3.0, azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-5 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-84304
HighCVSS 7.5

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

Mariner

Affected productsazl3 docker-cli 25.0.7-4 on Azure Linux 3.0, azl3 flannel 0.24.2-29 on Azure Linux 3.0, azl3 kubevirt 1.7.1-8 on Azure Linux 3.0, azl3 multus 4.0.2-10 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Ubuntu Security NoticesUSN-8675-2
Severity not listed

USN-8675-2: Perl vulnerabilities

USN-8675-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 26.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled short source addresses in the Socket module. An attacker could possibly use this issue ...

Vendor guidance

USN-8675-1 fixed vulnerabilities in Perl.

Microsoft Security Response CenterCVE-2026-73024
HighCVSS 7.8

Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.