Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,726 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
net: remove WARN_ON_ONCE() from sk_mc_loop()
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ata: pata_sl82c105: fix bridge revision use-after-free
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
HID: core: fix number/pointer type confusion on long items
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
io_uring: defer eventfd signaling when queued from a wakeup handler
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
xhci: dbgtty: Fix unregister on tty_register_driver() failure
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
KVM: s390: vsie: zero stale crypto bits
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
vlan: fix skb_under_panic and races when toggling HW VLAN offload
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
UEFI BIOS embedded Shell can be used to bypass Secure Boot
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
USN-8571-2: Apache HTTP Server regression
USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was incomplete due to a missing library symbol, resulting in a regression that could cause Apache HTTP Server to fail to start when HTTP/2 proxying was enabled. This update fixes the problem. We apologize for the...
USN-8571-1 fixed vulnerabilities in Apache HTTP Server.
CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machin...
CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library
Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identif...
A fix for this issue has been released and we recommend users of DJL upgrade to version 0.37.0 or later.
USN-8747-1: Beets vulnerability
It was discovered that Beets incorrectly escaped untrusted media metadata in its web interface. An attacker could possibly use this issue to inject arbitrary HTML or execute arbitrary JavaScript code in a user's browser.
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.