Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 27 minutes ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-61361
HighCVSS 7.0

Windows DHCP Client Remote Code Execution Vulnerability

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33296, 10.0.26100.33222, 10.0.26200.9168, 10.0.26200.9106
Vendor guidance

Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5121000.

Microsoft Security Response CenterCVE-2026-61353
HighCVSS 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-61345
HighCVSS 6.5

Microsoft Remote Registry Service Denial of Service Vulnerability

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-59138
HighCVSS 6.5

Microsoft Remote Registry Service Denial of Service Vulnerability

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-59137
HighCVSS 5.5

Windows Event Logging Service Information Disclosure Vulnerability

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-59136
HighCVSS 5.5

Microsoft COM for Windows Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-59135
HighCVSS 5.5

Microsoft Windows Search Component Information Disclosure Vulnerability

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-59132
HighCVSS 7.5

Windows TCP/IP Denial of Service Vulnerability

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-59128
HighCVSS 5.5

Windows Encrypting File System (EFS) Information Disclosure Vulnerability

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-6727
HighCVSS 5.9

MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

CVE-2026-6727 is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address th...

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5123303. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install ...

Microsoft Security Response CenterCVE-2026-49179
HighCVSS 8.8

Windows Active Directory Domain Services Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-54984
HighCVSS 7.8

Windows Imaging Component Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-54113
HighCVSS 7.5

Remote Procedure Call Denial of Service Vulnerability

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-40375
HighCVSS 6.5

Microsoft Dynamics Business Central Information Disclosure Vulnerability

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft Dynamics 365 Business Central 2024 Release Wave 2, Microsoft Dynamics 365 Business Central Release Wave 1 2025, Microsoft Dynamics 365 Business Central 2026 Release Wave 1, Microsoft Dynamics 365 Business Central Release Wave 2 2025
Fixed versions26.0.50788, 28.0.50938, 27.0.50789
Vendor guidance

Install KB5100263. Install KB5100266. Install KB5100265.

Microsoft Security Response CenterCVE-2026-63520
HighCVSS 8.1

Microsoft SharePoint Server Remote Code Execution Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.5565.1001, 16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-63516
HighCVSS 6.5

Microsoft SharePoint Server Spoofing Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Affected productsMicrosoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.5565.1001, 16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-63512
HighCVSS 6.5

Microsoft SharePoint Server Tampering Vulnerability

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

Affected productsMicrosoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.5565.1001, 16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-63514
HighCVSS 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.5565.1001, 16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-62837
HighCVSS 6.5

Microsoft SharePoint Server Information Disclosure Vulnerability

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.5565.1001, 16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-62829
HighCVSS 4.6

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Affected productsMicrosoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-57105
HighCVSS 8.0

Microsoft Office SharePoint Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Affected productsMicrosoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Fixed versions16.0.10417.20198, 16.0.19725.20522
Vendor guidance

Install KB5002894. Install KB5002896. Install KB5002893.

Microsoft Security Response CenterCVE-2026-56174
HighCVSS 7.8

Windows Narrator Braille Elevation of Privilege Vulnerability

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5120240.

Microsoft Security Response CenterCVE-2026-50472
HighCVSS 7.0

Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.