Vendor advisories

Microsoft Security Response Center

Browse 4,344 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,344 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-69314
HighCVSS 7.1

Windows Device Association Broker Service Elevation of Privilege Vulnerability

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-68894
HighCVSS 8.0

Windows Error Reporting Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-77490
MediumCVSS 6.1

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions151.0.4129.107
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-56855
MediumCVSS 7.5

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Mariner

Affected productsazl3 kubevirt 1.7.1-8 on Azure Linux 3.0, azl3 packer 1.9.5-18 on Azure Linux 3.0, azl3 cert-manager 1.12.15-11 on Azure Linux 3.0, azl3 cf-cli 8.7.11-8 on Azure Linux 3.0
Fixed versions8.7.11-9, 0.14.0-17, 2.27.0-14, 1.12.15-13
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-78662
MediumCVSS 7.5

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

Mariner

Affected productsazl3 cert-manager 1.12.15-11 on Azure Linux 3.0, azl3 kubernetes 1.30.10-27 on Azure Linux 3.0, azl3 moby-engine 25.0.3-19 on Azure Linux 3.0, azl3 cert-manager 1.12.15-12 on Azure Linux 3.0
Fixed versions1.12.15-13, 8.7.11-9, 0.14.0-17, 2.27.0-14
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-87587
HighCVSS 8.8

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Mariner

Affected productsazl3 nodejs 24.20.0-1 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.