Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-15771
Severity not listed

Chromium: CVE-2026-15771 Insufficient validation of untrusted input in Media

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.80
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-15769
Severity not listed

Chromium: CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-15778
Severity not listed

Chromium: CVE-2026-15778 Insufficient validation of untrusted input in Navigation

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.80
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-49174
HighCVSS 6.1

DNS Client Tampering Vulnerability

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50327
CriticalCVSS 7.8

Windows Media Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33158, 10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5099536. Install KB5101650. Install KB5101649.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.