Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 3 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-69654
HighCVSS 7.0

Windows Accounts Control Elevation of Privilege Vulnerability

Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-69652
HighCVSS 7.0

Windows Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-69648
HighCVSS 7.0

Windows Notification Elevation of Privilege Vulnerability

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725, 10.0.26100.33438
Vendor guidance

Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-69646
HighCVSS 8.3

Skype for Business Spoofing Vulnerability

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-69645
HighCVSS 7.0

Windows Message Queuing Elevation of Privilege Vulnerability

Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69643
HighCVSS 8.0

Windows Spaceport.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69642
HighCVSS 6.5

Skype for Business Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1
Fixed versions6.0.9319.885, 7.0.2046.569, 7.0.2046.879
Vendor guidance

Install KB5123301. Install KB5123300. Install KB5123287.

Microsoft Security Response CenterCVE-2026-69641
HighCVSS 9.1

Microsoft Exchange Server Elevation of Privilege Vulnerability

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server Subscription Edition RTM
Fixed versions15.01.2507.073, 15.02.1748.051, 15.02.1544.046, 15.02.2562.049
Vendor guidance

Install KB5121611. Install KB5121609. Install KB5121610. Install KB5121608.

Microsoft Security Response CenterCVE-2026-69638
HighCVSS 8.4

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69637
HighCVSS 5.7

Windows DHCP Server Denial of Service Vulnerability

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69636
HighCVSS 6.5

Microsoft Office SharePoint Information Disclosure Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SharePoint Server Subscription Edition
Fixed versions16.0.20326.20082
Vendor guidance

Install KB5002908.

Microsoft Security Response CenterCVE-2026-69631
HighCVSS 7.5

Windows DNS Denial of Service Vulnerability

Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69630
HighCVSS 7.0

Windows Win32k Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69629
HighCVSS 8.8

Microsoft Office Outlook Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.0.14334.20906, 16.0.17932.20976
Vendor guidance

Release Notes Install KB5002919.

Microsoft Security Response CenterCVE-2026-69628
HighCVSS 8.8

Windows iSCSI Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69627
HighCVSS 5.5

Windows Remote Desktop Licensing Service Information Disclosure Vulnerability

Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69626
HighCVSS 6.5

Microsoft Office Information Disclosure Vulnerability

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versions16.0.10417.20207, 16.0.20326.20138, 16.112.26083020, 16.0.14334.20906
Vendor guidance

Release Notes Install KB5002916.

Microsoft Security Response CenterCVE-2026-69625
HighCVSS 8.0

Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-69624
HighCVSS 6.5

Active Directory Certificate Services (AD CS) Tampering Vulnerability

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69623
HighCVSS 8.0

Windows HTTP Print Provider Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69621
HighCVSS 7.0

Role: Windows Fax Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69620
HighCVSS 8.1

Windows DHCP Server Remote Code Execution Vulnerability

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.26100.33438, 10.0.14393.9512
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69619
HighCVSS 8.0

Windows exFAT File System Elevation of Privilege Vulnerability

Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-69618
HighCVSS 5.5

Windows SMB Client Information Disclosure Vulnerability

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.