Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-62902
HighCVSS 6.5

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

Affected products.NET 8.0 installed on Windows, .NET 9.0 installed on Windows, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8
Fixed versions8.0.30, 9.0.19, 17.14.38, 18.8.3
Vendor guidance

Install KB5122104. Install KB5122105.

Microsoft Security Response CenterCVE-2026-62897
HighCVSS 7.0

.NET Framework Remote Code Execution Vulnerability

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

Affected productsMicrosoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems, .NET 10.0 installed on Windows
Fixed versions4.8.9344.0, 2.0.50727.9183 & 3.0.30729.9169, 10.0.11, 8.0.30
Vendor guidance

Install KB5120711. Install KB5120747. Install KB5122106. Install KB5122104. Install KB5122105. Install KB5120703. Install KB5120698.

Microsoft Security Response CenterCVE-2026-62688
HighCVSS 7.8

Windows MIDI Service Module Elevation of Privileges Vulnerability

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Affected productsWindows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems
Fixed versions10.0.26200.9168, 10.0.26200.9106, 10.0.26100.9168, 10.0.26100.9106
Vendor guidance

Install KB5121003. Install KB5120994. Install KB5121000.

Microsoft Security Response CenterCVE-2026-62695
HighCVSS 7.8

Windows Storage Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems
Fixed versions10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296, 10.0.26100.33222
Vendor guidance

Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-61346
HighCVSS 7.0

Windows Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.