Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,737Advisories collected
2,721Published or updated in 30 days
2,119Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,737 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-68831
HighCVSS 5.5

Windows Defender Firewall Service Information Disclosure Vulnerability

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-68830
HighCVSS 5.5

Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability

Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-68828
HighCVSS 8.8

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-68827
HighCVSS 8.0

Windows GDI+ Elevation of Privilege Vulnerability

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-68825
HighCVSS 7.0

Windows Bind Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems
Fixed versions10.0.26100.33438, 10.0.26200.9445, 10.0.22631.7582, 10.0.26100.9445
Vendor guidance

Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-68824
HighCVSS 7.0

Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725, 10.0.26100.33438
Vendor guidance

Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-68787
HighCVSS 7.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-68786
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68785
HighCVSS 4.9

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68784
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-68781
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-68780
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68779
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68778
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68777
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68776
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-68775
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-67648
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2019 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7
Vendor guidance

Install KB5122774. Install KB5122775. Install KB5122772. Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67645
HighCVSS 6.5

Microsoft SQL Server Information Disclosure Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32), Microsoft SQL Server 2025 for x64-based Systems (GDR)
Fixed versions14.0.3550.4, 15.0.2190.7, 15.0.4490.9, 17.0.1135.8
Vendor guidance

Install KB5122774. Install KB5122773. Install KB5122772. Install KB5122770. Install KB5122775. Install KB5122771. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-67642
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2025 for x64-based Systems (GDR)
Fixed versions17.0.4085.5, 17.0.1135.8
Vendor guidance

Install KB5122769. Install KB5122770.

Microsoft Security Response CenterCVE-2026-67641
HighCVSS 6.5

Microsoft SQL Server Denial of Service Vulnerability

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

Affected productsMicrosoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (CU8), Microsoft SQL Server 2022 for x64-based Systems (CU 26)
Fixed versions16.0.1200.5, 17.0.1135.8, 17.0.4085.5, 16.0.4275.2
Vendor guidance

Install KB5122771. Install KB5122770. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2026-67639
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67638
HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (CU8)
Fixed versions17.0.1135.8, 17.0.4085.5
Vendor guidance

Install KB5122770. Install KB5122769.

Microsoft Security Response CenterCVE-2026-67633
HighCVSS 6.5

Microsoft SQL Server Denial of Service Vulnerability

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Affected productsMicrosoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2017 for x64-based Systems (CU 31), Microsoft SQL Server 2022 for x64-based Systems (GDR)
Fixed versions14.0.2130.4, 15.0.2190.7, 14.0.3550.4, 16.0.1200.5
Vendor guidance

Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.