Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-58040
MediumCVSS 6.3

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Mariner

Affected productsazl3 nodejs 24.17.0-1 on Azure Linux 3.0
Fixed versions24.18.1-1
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-58043
HighCVSS 7.5

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.

Mariner

Affected productsazl3 nodejs 24.17.0-1 on Azure Linux 3.0
Fixed versions24.18.1-1
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-58039
LowCVSS 3.3

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Mariner

Affected productsazl3 nodejs 24.17.0-1 on Azure Linux 3.0
Fixed versions24.18.1-1
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-56847
LowCVSS 3.3

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Mariner

Affected productsazl3 nodejs 24.17.0-1 on Azure Linux 3.0
Fixed versions24.18.1-1
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-56850
MediumCVSS 4.1

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

Mariner

Affected productsazl3 nodejs 24.17.0-1 on Azure Linux 3.0
Fixed versions24.18.1-1
Vendor guidance

CBL-Mariner Releases

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.