Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-62777
HighCVSS 7.8

Windows License Manager Elevation of Privilege Vulnerability

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418.

Microsoft Security Response CenterCVE-2026-50313
HighCVSS 7.8

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-49162
HighCVSS 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33158, 10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-59126
HighCVSS 7.0

Windows Event Logging Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663, 10.0.19045.7663
Vendor guidance

Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-65671
HighCVSS 7.8

Remote Access API Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62746
HighCVSS 5.5

Win32k Information Disclosure Vulnerability

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-61347
HighCVSS 5.5

Windows Event Logging Service Information Disclosure Vulnerability

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-65796
CriticalCVSS 8.1

Windows iSCSI Target Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-65679
CriticalCVSS 8.1

Windows iSCSI Target Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-50309
HighCVSS 7.8

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50298
HighCVSS 6.8

Windows Spaceport.sys Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-62898
HighCVSS 7.5

Microsoft QUIC Information Disclosure Vulnerability

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

Affected products.NET 10.0 installed on Windows, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8, .NET 9.0 installed on Windows
Fixed versions10.0.11, 17.14.38, 18.8.3, 9.0.19
Vendor guidance

Install KB5122106. Install KB5122105. Install KB5122104.

Microsoft Security Response CenterCVE-2026-70354
HighCVSS 7.8

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

Affected productsMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems
Fixed versions2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0, 2.0.50727.8984 & 3.0.30729.8980, 2.0.50727.9183 & 3.0.30729.9169, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0
Vendor guidance

Install KB5120418. Install KB5120716. Install KB5120747. Install KB5120695. Install KB5120703. Install KB5120698. Install KB5120701. Install KB5120705. Install KB5120709. Install KB5120714. Install KB5120700. Install ...

Microsoft Security Response CenterCVE-2026-64906
HighCVSS 7.8

Microsoft Access Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versionshttps://aka.ms/OfficeSecurityReleases, 16.0.5565.1000
Vendor guidance

Click to Run Install KB5002832.

Microsoft Security Response CenterCVE-2026-62871
HighCVSS 7.8

.NET Elevation of Privilege Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

Affected products.NET 8.0 installed on Windows, .NET 9.0 installed on Windows, Microsoft Visual Studio 2026 version 18.8, Microsoft Visual Studio 2022 version 17.14
Fixed versions8.0.30, 9.0.19, 18.8.3, 17.14.38
Vendor guidance

Install KB5122104. Install KB5122105.

Microsoft Security Response CenterCVE-2026-61359
HighCVSS 7.8

Windows Storage Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems
Fixed versions10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296, 10.0.26100.33222
Vendor guidance

Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-62913
HighCVSS 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14
Fixed versions15.01.2507.072, 15.02.2562.046, 15.02.1748.049, 15.02.1544.044
Vendor guidance

Install KB5121576. Install KB5121573. Install KB5121574. Install KB5121575.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.