Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 4 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-59997
MediumCVSS 4.2

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

Mariner

Affected productsazl3 openssh 9.8p1-8 on Azure Linux 3.0
Fixed versions9.8p1-9
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-45489
MediumCVSS 6.5

Microsoft Edge (Chromium-based) Spoofing Vulnerability

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-14428
Severity not listed

Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-14382
Severity not listed

Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-14114
Severity not listed

Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13995
Severity not listed

Chromium: CVE-2026-13995 Insufficient validation of untrusted input in Autofill

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13994
Severity not listed

Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13964
Severity not listed

Chromium: CVE-2026-13964 Insufficient policy enforcement in WebView

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13955
Severity not listed

Chromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabs

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13949
Severity not listed

Chromium: CVE-2026-13949 Insufficient policy enforcement in Payments

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.