Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked about an hour ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-15124
Severity not listed

Chromium: CVE-2026-15124 Insufficient policy enforcement in Passwords

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.65
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-15122
Severity not listed

Chromium: CVE-2026-15122 Insufficient validation of untrusted input in Codecs

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.65
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-15119
Severity not listed

Chromium: CVE-2026-15119 Inappropriate implementation in GetUserMedia

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.65
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-15114
Severity not listed

Chromium: CVE-2026-15114 Out of bounds read and write in Codecs

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.65
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13283
Severity not listed

Chromium: CVE-2026-13282: Use after free in Payments

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions149.0.4022.105
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-47301
HighCVSS 8.8

Configuration Manager Elevation of Privilege Vulnerability

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft Configuration Manager 2509, Microsoft Configuration Manager 2603, Microsoft Configuration Manager 2503
Fixed versions5.0.9141.1030, 5.0.9146.1021, 5.0.9135.1031
Vendor guidance

Install KB37864969. Install KB38232642.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.