Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,737Advisories collected
2,721Published or updated in 30 days
2,119Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,737 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-66308
HighCVSS 6.5

Skype for Business and Lync Denial of Service Vulnerability

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2019 CU8
Fixed versions6.0.9319.885, 7.0.2046.879, 7.0.2046.569
Vendor guidance

Install KB5123301. Install KB5123287. Install KB5123300.

Microsoft Security Response CenterCVE-2026-66307
HighCVSS 7.5

Skype for Business and Lync Denial of Service Vulnerability

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2019 CU8
Fixed versions6.0.9319.885, 7.0.2046.879, 7.0.2046.569
Vendor guidance

Install KB5123301. Install KB5123287. Install KB5123300.

Microsoft Security Response CenterCVE-2026-66306
HighCVSS 6.5

Skype for Business Information Disclosure Vulnerability

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-66305
HighCVSS 7.1

Skype for Business Spoofing Vulnerability

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1
Fixed versions6.0.9319.885, 7.0.2046.569, 7.0.2046.879
Vendor guidance

Install KB5123301. Install KB5123300. Install KB5123287.

Microsoft Security Response CenterCVE-2026-66304
HighCVSS 7.5

Skype for Business Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Affected productsSkype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13
Fixed versions7.0.2046.569, 7.0.2046.879, 6.0.9319.885
Vendor guidance

Install KB5123300. Install KB5123287. Install KB5123301.

Microsoft Security Response CenterCVE-2026-66303
HighCVSS 6.5

Skype for Business and Lync Denial of Service Vulnerability

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, Skype for Business Server Subscription Edition CU1
Fixed versions6.0.9319.885, 7.0.2046.569, 7.0.2046.879
Vendor guidance

Install KB5123301. Install KB5123300. Install KB5123287.

Microsoft Security Response CenterCVE-2026-64918
HighCVSS 6.5

Microsoft Office Spoofing Vulnerability

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versionshttps://aka.ms/OfficeSecurityReleases, 16.0.17932.20960, 16.0.5569.1003
Vendor guidance

Click to Run Release Notes Install KB5002916.

Microsoft Security Response CenterCVE-2026-63523
HighCVSS 6.5

Skype for Business Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Affected productsSkype for Business Server 2015 CU13, Skype for Business Server Subscription Edition CU1, Skype for Business Server 2019 CU8
Fixed versions6.0.9319.885, 7.0.2046.879, 7.0.2046.569
Vendor guidance

Install KB5123301. Install KB5123287. Install KB5123300.

Microsoft Security Response CenterCVE-2026-62813
HighCVSS 7.5

Windows Active Directory Domain Services Remote Code Execution Vulnerability

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-62810
HighCVSS 7.8

Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-62804
HighCVSS 7.8

Microsoft Word Remote Code Execution Vulnerability

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versionshttps://aka.ms/OfficeSecurityReleases, 16.0.17932.20960, 16.0.5569.1002
Vendor guidance

Click to Run Release Notes Install KB5002923.

Microsoft Security Response CenterCVE-2026-62801
HighCVSS 6.5

Microsoft PowerShell Security Feature Bypass Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-62762
HighCVSS 6.5

Windows Active Directory Domain Services Denial of Service Vulnerability

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-62759
HighCVSS 7.5

Windows Netlogon Spoofing Vulnerability

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-62744
HighCVSS 8.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33438, 10.0.26200.9445, 10.0.26100.9445, 10.0.28000.2954
Vendor guidance

Install KB5122871. Install KB5124008. Install KB5124012.

Microsoft Security Response CenterCVE-2026-62706
HighCVSS 8.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-62697
HighCVSS 7.8

Windows Push Notifications Elevation of Privilege Vulnerability

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems
Fixed versions10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725, 10.0.26100.33438
Vendor guidance

Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-62694
HighCVSS 7.0

Windows Installer Elevation of Privilege Vulnerability

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-58649
HighCVSS 6.5

.NET Information Disclosure Vulnerability

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Visual Studio 2022 version 17.14, .NET 11.0 installed on Linux, .NET 11.0 installed on Mac OS, .NET 8.0 installed on Windows
Fixed versions17.14.40, 11.0 RC1, 8.0.130, 8.0.424, 9.0.120, 9.0.317
Vendor guidance

Release Notes Install KB5126104. Install KB5126105. Install KB5126106.

Microsoft Security Response CenterCVE-2026-58600
HighCVSS 7.8

HEVC Video Extensions Elevation of Privilege Vulnerability

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

Affected productsHEVC Video Extensions, HEVC Video Extensions for Licensed Applications, HEVC Video Extensions from Device Manufacturer on Windows 10 Version 1809 for 32-bit Systems, HEVC Video Extensions from Device Manufacturer on Windows 10 Version 1809 for x64-based Systems
Fixed versions2.4.87.0, 2.4.85.0, 2.4.86.0, 2.5.25.0
Vendor guidance

Update Information

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.