Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,726Advisories collected
2,720Published or updated in 30 days
2,115Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,726 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-87587
HighCVSS 8.8

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Mariner

Affected productsazl3 nodejs 24.20.0-1 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-87612
HighCVSS 8.8

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Mariner

Affected productsazl3 nodejs 24.20.0-1 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-87536
HighCVSS 8.8

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Mariner

Affected productsazl3 nodejs 24.20.0-1 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-87625
HighCVSS 8.8

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

Mariner

Affected productsazl3 nodejs 24.20.0-1 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-87601
MediumCVSS 7.5

Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Mariner

Affected productsazl3 nodejs 24.20.0-1 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Ubuntu Security NoticesUSN-8571-2
Severity not listed

USN-8571-2: Apache HTTP Server regression

USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was incomplete due to a missing library symbol, resulting in a regression that could cause Apache HTTP Server to fail to start when HTTP/2 proxying was enabled. This update fixes the problem. We apologize for the...

Vendor guidance

USN-8571-1 fixed vulnerabilities in Apache HTTP Server.

AWS Security BulletinsCVE-2026-89049
Severity not listed

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machin...

AWS Security BulletinsCVE-2026-85228
Severity not listed

CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library

Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identif...

Vendor guidance

A fix for this issue has been released and we recommend users of DJL upgrade to version 0.37.0 or later.

Ubuntu Security NoticesUSN-8747-1
Severity not listed

USN-8747-1: Beets vulnerability

It was discovered that Beets incorrectly escaped untrusted media metadata in its web interface. An attacker could possibly use this issue to inject arbitrary HTML or execute arbitrary JavaScript code in a user's browser.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.