Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,726Advisories collected
2,710Published or updated in 30 days
2,115Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,726 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-69601
CriticalCVSS 8.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69595
CriticalCVSS 9.8

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Affected productsWindows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69590
CriticalCVSS 9.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69579
CriticalCVSS 9.8

Windows Message Queuing Remote Code Execution Vulnerability

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69530
CriticalCVSS 8.1

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871.

Microsoft Security Response CenterCVE-2026-69518
CriticalCVSS 8.8

Windows Remote Desktop Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69501
CriticalCVSS 7.0

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725, 10.0.26100.33438
Vendor guidance

Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-69499
CriticalCVSS 8.8

Windows Imaging Component Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69285
CriticalCVSS 8.8

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002916.

Microsoft Security Response CenterCVE-2026-67643
CriticalCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2025 for x64-based Systems (CU8)
Fixed versions16.0.1200.5, 17.0.1135.8, 16.0.4275.2, 17.0.4085.5
Vendor guidance

Install KB5122771. Install KB5122770. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67636
CriticalCVSS 8.5

Microsoft SQL Server Remote Code Execution Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32)
Fixed versions15.0.2190.7, 16.0.1200.5, 17.0.1135.8, 15.0.4490.9
Vendor guidance

Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67631
CriticalCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions17.0.4085.5, 16.0.4275.2, 14.0.2130.4, 15.0.2190.7
Vendor guidance

Install KB5122769. Install KB5122768. Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772.

Microsoft Security Response CenterCVE-2026-67378
CriticalCVSS 8.5

Microsoft SQL Server Remote Code Execution Vulnerability

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32)
Fixed versions15.0.2190.7, 16.0.1200.5, 17.0.1135.8, 15.0.4490.9
Vendor guidance

Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-66302
CriticalCVSS 9.8

Skype for Business Remote Code Execution Vulnerability

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-58599
CriticalCVSS 7.8

HEVC Video Extensions Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Affected productsHEVC Video Extensions, HEVC Video Extensions for Licensed Applications, HEVC Video Extensions from Device Manufacturer on Windows 10 Version 1809 for 32-bit Systems, HEVC Video Extensions from Device Manufacturer on Windows 10 Version 1809 for x64-based Systems
Fixed versions2.4.87.0, 2.4.85.0, 2.4.86.0, 2.5.25.0
Vendor guidance

Update Information

Microsoft Security Response CenterCVE-2026-34182
CriticalCVSS 9.1

CMS AuthEnvelopedData Processing May Accept Forged Messages

Mariner

Affected productsMicrosoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10), Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8), azl3 edk2 20240524git3e722403cd16-17 on Azure Linux 3.0
Fixed versions16.11.60, 15.9.83, 17.14.40, 20240524git3e722403cd16-18
Vendor guidance

Release Notes CBL-Mariner Releases

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.