Vendor advisories

Microsoft Security Response Center

Browse 4,344 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,344 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-85046
Severity not listed

Chromium: CVE-2026-85046 Type confusion in V8

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.62
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-85091
HighCVSS 7.4

zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate

Mariner

Affected productsazl3 zlib 1.3.2-1 on Azure Linux 3.0, azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-5 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-84304
HighCVSS 7.5

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

Mariner

Affected productsazl3 docker-cli 25.0.7-4 on Azure Linux 3.0, azl3 flannel 0.24.2-29 on Azure Linux 3.0, azl3 kubevirt 1.7.1-8 on Azure Linux 3.0, azl3 multus 4.0.2-10 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.