Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked about an hour ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-72966
HighCVSS 5.5

Windows Remote Access Connection Manager Tampering Vulnerability

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72965
HighCVSS 7.8

Windows WebClient Service Elevation of Privilege Vulnerability

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72963
HighCVSS 7.0

Windows Modern Execution Server Elevation of Privilege Vulnerability

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-72956
HighCVSS 6.5

Microsoft Office PowerPoint Information Disclosure Vulnerability

Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-72953
HighCVSS 7.8

Windows USB Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725, 10.0.26100.33438
Vendor guidance

Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-72952
HighCVSS 7.0

Windows Spaceport.sys Remote Code Execution Vulnerability

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-72949
HighCVSS 7.5

Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.26100.33438, 10.0.26200.9445, 10.0.22631.7582
Vendor guidance

Install KB5122882. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-72948
HighCVSS 6.7

Windows DNS Elevation of Privilege Vulnerability

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72947
HighCVSS 6.4

Windows File History Service Elevation of Privilege Vulnerability

Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.26200.9445
Vendor guidance

Install KB5122876. Install KB5122878. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-72946
HighCVSS 7.8

Microsoft Storage Port Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33438, 10.0.26200.9445, 10.0.26100.9445, 10.0.28000.2954
Vendor guidance

Install KB5122871. Install KB5124008. Install KB5124012.

Microsoft Security Response CenterCVE-2026-72945
HighCVSS 5.5

Windows Task Scheduler Information Disclosure Vulnerability

Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122880. Install KB5123099.

Microsoft Security Response CenterCVE-2026-72944
HighCVSS 7.8

Role: Windows Fax Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72943
HighCVSS 7.5

Windows Deployment Services Remote Code Execution Vulnerability

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72942
HighCVSS 6.5

Windows Spaceport.sys Information Disclosure Vulnerability

Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72941
HighCVSS 7.8

Windows Biometric Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-72940
HighCVSS 8.8

Windows Schannel Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.26100.33438, 10.0.26200.9445, 10.0.22631.7582
Vendor guidance

Install KB5122882. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-72939
HighCVSS 6.5

Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72938
HighCVSS 6.5

Microsoft Office PowerPoint Information Disclosure Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office LTSC 2024 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft Office LTSC 2021 for 32-bit editions, Microsoft Office 2019 for 32-bit editions
Fixed versions16.0.17932.20976, 16.0.20326.20138, 16.0.14334.20906, 16.0.10417.20207
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-72937
HighCVSS 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72936
HighCVSS 8.1

Windows SMB Client Remote Code Execution Vulnerability

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.26100.33438, 10.0.26200.9445, 10.0.22631.7582
Vendor guidance

Install KB5122882. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-72935
HighCVSS 6.7

Windows NTFS Elevation of Privilege Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72933
HighCVSS 8.8

Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72932
HighCVSS 7.5

Windows Message Queuing Queue Manager Information Disclosure Vulnerability

Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-72931
HighCVSS 4.7

Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.