Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 5 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-38968
CriticalCVSS 9.8

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

Mariner

Affected productsazl3 ntopng 5.2.1-6 on Azure Linux 3.0
Microsoft Security Response CenterCVE-2026-14131
Severity not listed

Chromium: CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-14020
Severity not listed

Chromium: CVE-2026-14020 Insufficient validation of untrusted input in WebXR

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13953
Severity not listed

Chromium: CVE-2026-13953 Inappropriate implementation in SplitView

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13874
Severity not listed

Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-14019
Severity not listed

Chromium: CVE-2026-14019 Inappropriate implementation in Passwords

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13952
Severity not listed

Chromium: CVE-2026-13952 Inappropriate implementation in PerformanceAPIs

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-13797
Severity not listed

Chromium: CVE-2026-13797 Insufficient validation of untrusted input in Chromecast

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions150.0.4078.48
Vendor guidance

Release Notes

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.