Vendor advisories

Microsoft Security Response Center

Browse 4,344 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 5 hours ago Checked every 6 hours

4,344 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-69285
CriticalCVSS 8.8

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002916.

Microsoft Security Response CenterCVE-2026-67643
CriticalCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2025 for x64-based Systems (CU8)
Fixed versions16.0.1200.5, 17.0.1135.8, 16.0.4275.2, 17.0.4085.5
Vendor guidance

Install KB5122771. Install KB5122770. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67636
CriticalCVSS 8.5

Microsoft SQL Server Remote Code Execution Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32)
Fixed versions15.0.2190.7, 16.0.1200.5, 17.0.1135.8, 15.0.4490.9
Vendor guidance

Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67631
CriticalCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions17.0.4085.5, 16.0.4275.2, 14.0.2130.4, 15.0.2190.7
Vendor guidance

Install KB5122769. Install KB5122768. Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772.

Microsoft Security Response CenterCVE-2026-67378
CriticalCVSS 8.5

Microsoft SQL Server Remote Code Execution Vulnerability

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32)
Fixed versions15.0.2190.7, 16.0.1200.5, 17.0.1135.8, 15.0.4490.9
Vendor guidance

Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-66302
CriticalCVSS 9.8

Skype for Business Remote Code Execution Vulnerability

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-58599
CriticalCVSS 7.8

HEVC Video Extensions Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Affected productsHEVC Video Extensions, HEVC Video Extensions for Licensed Applications, HEVC Video Extensions from Device Manufacturer on Windows 10 Version 1809 for 32-bit Systems, HEVC Video Extensions from Device Manufacturer on Windows 10 Version 1809 for x64-based Systems
Fixed versions2.4.87.0, 2.4.85.0, 2.4.86.0, 2.5.25.0
Vendor guidance

Update Information

Microsoft Security Response CenterCVE-2026-34182
CriticalCVSS 9.1

CMS AuthEnvelopedData Processing May Accept Forged Messages

Mariner

Affected productsMicrosoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10), Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8), azl3 edk2 20240524git3e722403cd16-17 on Azure Linux 3.0
Fixed versions16.11.60, 15.9.83, 17.14.40, 20240524git3e722403cd16-18
Vendor guidance

Release Notes CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-85880
HighCVSS 7.8

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-85875
HighCVSS 5.5

Microsoft Office Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected productsMicrosoft Office 2016 (64-bit edition), Microsoft Office 2016 (32-bit edition), Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft Office LTSC 2024 for 32-bit editions
Fixed versions16.0.5569.1003, 16.0.20326.20138, 16.0.17932.20976, 16.0.10417.20207
Vendor guidance

Release Notes Install KB5002904. Install KB5002914.

Microsoft Security Response CenterCVE-2026-85360
HighCVSS 7.0

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-84003
HighCVSS 7.4

Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Affected productsMicrosoft Authentication Library (MSAL) for Node.js
Fixed versions5.6.0
Vendor guidance

Release Notes

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.