Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-50314
CriticalCVSS 7.8

Microsoft Office Remote Code Execution Vulnerability

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected productsMicrosoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Fixed versions16.111.26071215, https://aka.ms/OfficeSecurityReleases, 16.0.5561.1000
Vendor guidance

Release Notes Click to Run Install KB5002887.

Microsoft Security Response CenterCVE-2026-49796
CriticalCVSS 7.8

Windows GDI+ Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-49164
CriticalCVSS 8.1

Windows Active Directory Domain Services Remote Code Execution Vulnerability

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-48564
CriticalCVSS 8.8

DHCP Server Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.26100.33158, 10.0.14393.9339
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099536. Install KB5099535. Install KB5094042. Install KB5094041.

Microsoft Security Response CenterCVE-2026-42982
CriticalCVSS 7.8

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5099414. Install KB5101649. Install KB5095051. Install KB5099535.

Microsoft Security Response CenterCVE-2026-50337
HighCVSS 7.8

Windows Notification Elevation of Privilege Vulnerability

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535.

Microsoft Security Response CenterCVE-2026-50336
HighCVSS 7.8

Windows Media Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.

Affected productsWindows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems
Fixed versions10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50335
HighCVSS 7.8

Windows Operating Systems Elevation of Privilege Vulnerability

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50334
HighCVSS 5.5

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50332
HighCVSS 7.8

Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50331
HighCVSS 7.8

Windows Application Model Core API Elevation of Privilege Vulnerability

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535.

Microsoft Security Response CenterCVE-2026-50330
HighCVSS 7.5

Windows Remote Desktop Client Elevation of Privilege Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50329
HighCVSS 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50328
HighCVSS 7.5

Windows Server Update Service (WSUS) Tampering Vulnerability

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.26100.33158, 10.0.14393.9339
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099536. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50326
HighCVSS 7.8

Windows Unified Consent System Elevation of Privilege Vulnerability

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems
Fixed versions10.0.19044.7548, 10.0.19045.7548, 10.0.26100.33158, 10.0.26200.8875
Vendor guidance

Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50325
HighCVSS 7.0

Win32k Elevation of Privilege Vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50323
HighCVSS 7.0

Windows Runtime Elevation of Privilege Vulnerability

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33158, 10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50322
HighCVSS 7.0

Windows Runtime Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33158, 10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50321
HighCVSS 7.8

Windows USB Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-50318
HighCVSS 7.8

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535.

Microsoft Security Response CenterCVE-2026-50317
HighCVSS 7.8

Windows Operating Systems Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33158, 10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50316
HighCVSS 5.5

Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Affected productsWindows Server 2022, Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems
Fixed versions10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.33158
Vendor guidance

Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649.

Microsoft Security Response CenterCVE-2026-50315
HighCVSS 7.8

Windows Image Acquisition Elevation of Privilege Vulnerability

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33158, 10.0.26200.8875, 10.0.26100.8875, 10.0.28000.2525
Vendor guidance

Install KB5099536. Install KB5101650. Install KB5101649.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.