Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,726 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
USN-8746-1: libEBML vulnerability
It was discovered that libEBML incorrectly handled certain read and write operations. An attacker could possibly use this issue to cause a buffer overflow, resulting in a denial of service.
USN-8745-1: KissFFT vulnerabilities
It was discovered that KissFFT incorrectly handled certain large Fourier transform sizes on 32-bit architectures. An attacker could possibly use this issue to cause KissFFT to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2025-34297) It was discovere...
USN-8748-1: Linux kernel (NVIDIA) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - G...
This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - GFS2 file system; - OCFS2 file system; - SMB network file system;...
USN-8744-1: Python vulnerabilities
It was discovered that Python's http.cookies module incorrectly handled control characters in certain cookie operations. An attacker could possibly use this issue to inject arbitrary content. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu...
USN-8743-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled backslash escaping in the PostgreSQL extension. An attacker could use this issue to perform SQL injection attacks. (CVE-2026-17543) It was discovered that PHP incorrectly handled certain inputs to the bccomp() function. An attacke...
USN-8737-2: GNU C Library vulnerabilities
USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An att...
USN-8737-1 fixed vulnerabilities in GNU C Library.
USN-8742-1: Netty vulnerability
It was discovered that Netty incorrectly validates the bailiwick of NS records. An attacker could possibly use this issue to facilitate DNS cache poisoning attacks.
USN-8741-1: Flatpak vulnerabilities
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubu...
USN-8740-1: .NET vulnerabilities
Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did not properly validate cross-origin WebSocket connections. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-58649) Rajesh Chada discovered that the .NET watch AspireS...
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
httpc does not bound server-supplied numeric header values before integer conversion
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
eldap does not bound the port component of a referral URL before integer conversion
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.