Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 56 minutes ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-67385
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-67384
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67383
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (CU8)
Fixed versions17.0.1135.8, 17.0.4085.5
Vendor guidance

Install KB5122770. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67381
HighCVSS 8.8

Microsoft SQL Server Elevation of Privilege Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions16.0.4275.2, 17.0.4085.5, 14.0.2130.4, 15.0.2190.7
Vendor guidance

Install KB5122768. Install KB5122769. Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772.

Microsoft Security Response CenterCVE-2026-67380
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-67379
HighCVSS 8.5

Microsoft SQL Server Remote Code Execution Vulnerability

Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions17.0.4085.5, 16.0.4275.2, 15.0.2190.7, 16.0.1200.5
Vendor guidance

Install KB5122769. Install KB5122768. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772.

Microsoft Security Response CenterCVE-2026-67376
HighCVSS 7.5

Microsoft SQL Server Denial of Service Vulnerability

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-67373
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (CU8)
Fixed versions17.0.1135.8, 17.0.4085.5
Vendor guidance

Install KB5122770. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67370
HighCVSS 8.8

Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2022 for x64-based Systems (CU 26), Microsoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions16.0.4275.2, 17.0.4085.5, 14.0.2130.4, 15.0.2190.7
Vendor guidance

Install KB5122768. Install KB5122769. Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772.

Microsoft Security Response CenterCVE-2026-67369
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (CU8)
Fixed versions17.0.1135.8, 17.0.4085.5
Vendor guidance

Install KB5122770. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67368
HighCVSS 8.8

Microsoft SQL Server Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-66820
HighCVSS 8.8

SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-66819
HighCVSS 8.8

Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-66818
HighCVSS 8.8

Microsoft SQL Server Elevation of Privilege Vulnerability

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-66816
HighCVSS 6.5

Microsoft SQL Server Security Feature Bypass Vulnerability

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Affected productsMicrosoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2022 for x64-based Systems (CU 26)
Fixed versions16.0.1200.5, 17.0.1135.8, 17.0.4085.5, 16.0.4275.2
Vendor guidance

Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-66814
HighCVSS 8.8

Microsoft SQL Server Elevation of Privilege Vulnerability

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-66308
HighCVSS 6.5

Skype for Business and Lync Denial of Service Vulnerability

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2019 CU8
Fixed versions6.0.9319.885, 7.0.2046.879, 7.0.2046.569
Vendor guidance

Install KB5123301. Install KB5123287. Install KB5123300.

Microsoft Security Response CenterCVE-2026-66307
HighCVSS 7.5

Skype for Business and Lync Denial of Service Vulnerability

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2019 CU8
Fixed versions6.0.9319.885, 7.0.2046.879, 7.0.2046.569
Vendor guidance

Install KB5123301. Install KB5123287. Install KB5123300.

Microsoft Security Response CenterCVE-2026-66306
HighCVSS 6.5

Skype for Business Information Disclosure Vulnerability

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-66305
HighCVSS 7.1

Skype for Business Spoofing Vulnerability

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1
Fixed versions6.0.9319.885, 7.0.2046.569, 7.0.2046.879
Vendor guidance

Install KB5123301. Install KB5123300. Install KB5123287.

Microsoft Security Response CenterCVE-2026-66304
HighCVSS 7.5

Skype for Business Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-66303
HighCVSS 6.5

Skype for Business and Lync Denial of Service Vulnerability

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1
Fixed versions6.0.9319.885, 7.0.2046.569, 7.0.2046.879
Vendor guidance

Install KB5123301. Install KB5123300. Install KB5123287.

Microsoft Security Response CenterCVE-2026-64918
HighCVSS 6.5

Microsoft Office Spoofing Vulnerability

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versionshttps://aka.ms/OfficeSecurityReleases, 16.0.17932.20960, 16.0.5569.1003
Vendor guidance

Click to Run Release Notes Install KB5002916.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.