Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 11 minutes ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-80079
HighCVSS 6.5

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-80078
HighCVSS 6.5

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.112.26083020, 16.0.14334.20906
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-80076
HighCVSS 6.5

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.112.26083020, 16.0.14334.20906
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-80075
HighCVSS 7.8

Windows Work Folders Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123066.

Microsoft Security Response CenterCVE-2026-80073
HighCVSS 6.5

Microsoft Office Outlook Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002919.

Microsoft Security Response CenterCVE-2026-78526
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.112.26083020, 16.0.14334.20906
Vendor guidance

Release Notes Install KB5002898.

Microsoft Security Response CenterCVE-2026-78524
HighCVSS 8.8

Microsoft Office Remote Code Execution Vulnerability

Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002916.

Microsoft Security Response CenterCVE-2026-78523
HighCVSS 5.9

Windows DNS Server Denial of Service Vulnerability

Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-78522
HighCVSS 6.5

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-78521
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-78518
HighCVSS 8.8

Microsoft Office Excel Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002914. Install KB5002904.

Microsoft Security Response CenterCVE-2026-78517
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-78516
HighCVSS 4.3

Windows Storage Information Disclosure Vulnerability

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-78515
HighCVSS 6.5

Microsoft Office Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.112.26083020, 16.0.14334.20906
Vendor guidance

Release Notes Install KB5002916.

Microsoft Security Response CenterCVE-2026-78514
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-78513
HighCVSS 5.5

Microsoft Office PowerPoint Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.112.26083020, 16.0.14334.20906
Vendor guidance

Release Notes Install KB5002920.

Microsoft Security Response CenterCVE-2026-78512
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB4011160. Install KB5002914.

Microsoft Security Response CenterCVE-2026-78511
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-78508
HighCVSS 4.6

Windows CD-ROM Driver Information Disclosure Vulnerability

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-78507
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-78506
HighCVSS 5.5

Microsoft Office Word Information Disclosure Vulnerability

Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-78504
HighCVSS 8.8

Microsoft Office Word Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002923.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.