Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,726 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Windows DHCP Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network.
Install KB5124008. Install KB5124012.
Windows MIDI Service Module Elevation of Privileges Vulnerability
Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Install KB5124008. Install KB5124012.
Windows Partition Management Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Storage Spaces Controller Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.
OpenLDAP SASL authentication bypass
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Negotiate ambient user conn reuse
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Gfs2-utils: gfs2-utils: stack overflow via alloca(1
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
USN-8739-1: ImageMagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366...
USN-8670-3: curl vulnerability
USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in th...
USN-8670-1 fixed a vulnerability in curl.
USN-8679-2: Vim vulnerability
USN-8679-1 fixed a vulnerability in Vim. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: It was discovered that Vim incorrectly handled certain tags files. An attacker could possibly use this issue to execute arbitrary code.
USN-8679-1 fixed a vulnerability in Vim.
USN-8738-1: FFmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled certain video frames when using the hqdn3d filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036) Adrian Junge discovered that FFmpeg incorrectly handled certa...
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker ...
Cisco has released software updates that address this vulnerability.
USN-8737-1: GNU C Library vulnerabilities
It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-...
September 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and ...
Ivanti releases standard security patches on the second Tuesday of every month.
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.