Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 4 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-62880
HighCVSS 7.8

Windows NTFS Elevation of Privilege Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62872
HighCVSS 8.8

.NET Framework Elevation of Privilege Vulnerability

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
Fixed versions4.8.4805.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0
Vendor guidance

Install KB5120702. Install KB5120703. Install KB5120706. Install KB5120701. Install KB5120698. Install KB5120418. Install KB5120699. Install KB5120700. Install KB5120711. Install KB5120714. Install KB5120709. Install ...

Microsoft Security Response CenterCVE-2026-62832
HighCVSS 7.8

Windows User Profile Service Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663, 10.0.19045.7663
Vendor guidance

Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-62814
HighCVSS 6.5

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-62811
HighCVSS 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems
Fixed versions10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296, 10.0.26100.33222
Vendor guidance

Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-62807
HighCVSS 7.8

Windows DHCP Server Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-62803
HighCVSS 7.8

Windows DHCP Server Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-62793
HighCVSS 5.5

Windows NTFS Information Disclosure Vulnerability

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62790
HighCVSS 8.8

Windows SMBv3 Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62788
HighCVSS 7.0

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems
Fixed versions10.0.26100.33296, 10.0.26100.33222, 10.0.26200.9168, 10.0.26200.9106
Vendor guidance

Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-62786
HighCVSS 5.5

Win32k Information Disclosure Vulnerability

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62800
HighCVSS 8.8

Windows SMBv3 Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62781
HighCVSS 8.1

RPC Runtime Library Remote Code Execution Vulnerability

Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62782
HighCVSS 6.5

Windows SMB Client Information Disclosure Vulnerability

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418.

Microsoft Security Response CenterCVE-2026-62780
HighCVSS 7.0

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems
Fixed versions10.0.26100.33296, 10.0.26100.33222, 10.0.26200.9168, 10.0.26200.9106
Vendor guidance

Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-62778
HighCVSS 8.1

Windows DNS Elevation of Privilege Vulnerability

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-62776
HighCVSS 7.8

Windows DHCP Server Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-62775
HighCVSS 5.5

Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

Affected productsWindows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems
Fixed versions10.0.28000.2704
Vendor guidance

Install KB5121000.

Microsoft Security Response CenterCVE-2026-62770
HighCVSS 7.8

Windows Shell Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62768
HighCVSS 7.8

Windows Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62761
HighCVSS 7.8

Windows DHCP Server Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-62769
HighCVSS 6.7

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62752
HighCVSS 7.8

Windows Kerberos Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.