Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,726Advisories collected
2,720Published or updated in 30 days
2,115Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,726 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Ubuntu Security NoticesUSN-8746-1
Severity not listed

USN-8746-1: libEBML vulnerability

It was discovered that libEBML incorrectly handled certain read and write operations. An attacker could possibly use this issue to cause a buffer overflow, resulting in a denial of service.

Ubuntu Security NoticesUSN-8748-1
Severity not listed

USN-8748-1: Linux kernel (NVIDIA) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - G...

Vendor guidance

This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - GFS2 file system; - OCFS2 file system; - SMB network file system;...

Ubuntu Security NoticesUSN-8737-2
Severity not listed

USN-8737-2: GNU C Library vulnerabilities

USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An att...

Vendor guidance

USN-8737-1 fixed vulnerabilities in GNU C Library.

Ubuntu Security NoticesUSN-8742-1
Severity not listed

USN-8742-1: Netty vulnerability

It was discovered that Netty incorrectly validates the bailiwick of NS records. An attacker could possibly use this issue to facilitate DNS cache poisoning attacks.

Ubuntu Security NoticesUSN-8740-1
Severity not listed

USN-8740-1: .NET vulnerabilities

Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did not properly validate cross-origin WebSocket connections. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-58649) Rajesh Chada discovered that the .NET watch AspireS...

Microsoft Security Response CenterCVE-2026-85507
CriticalCVSS 9.8

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

Mariner

Affected productsazl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Fixed versions1.6.19-1
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-85506
CriticalCVSS 9.8

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

Mariner

Affected productsazl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Fixed versions1.6.19-1
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-85505
MediumCVSS 7.5

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

Mariner

Affected productsazl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Fixed versions1.6.19-1
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-85508
CriticalCVSS 9.8

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

Mariner

Affected productsazl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Fixed versions1.6.19-1
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-85504
CriticalCVSS 9.8

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

Mariner

Affected productsazl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Fixed versions1.6.19-1
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-75538
High

A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer

Mariner

Affected productsazl3 erlang 26.2.5.21-4 on Azure Linux 3.0, azl3 erlang 26.2.5.21-6 on Azure Linux 3.0
Fixed versions26.2.5.21-6
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.