Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,737Advisories collected
2,716Published or updated in 30 days
2,119Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,737 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-56198
HighCVSS 7.8

Microsoft Trace Data Helper Elevation of Privilege Vulnerability

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

Affected productsWindows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems
Fixed versions10.0.26100.33438, 10.0.26200.9445, 10.0.26100.9445, 10.0.28000.2954
Vendor guidance

Install KB5122871. Install KB5124008. Install KB5124012.

Microsoft Security Response CenterCVE-2026-56177
HighCVSS 7.8

Windows Server Elevation of Privilege Vulnerability

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.

Microsoft Security Response CenterCVE-2026-56172
HighCVSS 7.8

Windows VHD miniport driver Elevation of Privilege Vulnerability

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.

Microsoft Security Response CenterCVE-2026-55007
HighCVSS 8.1

Microsoft Exchange Server Remote Code Execution Vulnerability

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM
Fixed versions15.02.1544.046, 15.02.1748.051, 15.02.2562.049
Vendor guidance

Install KB5121610. Install KB5121609. Install KB5121608.

Microsoft Security Response CenterCVE-2026-50349
HighCVSS 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9245, 10.0.20348.5622, 10.0.19044.7725, 10.0.19045.7725
Vendor guidance

Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.

Microsoft Security Response CenterCVE-2026-47297
HighCVSS 8.1

Microsoft SQL Server Remote Code Execution Vulnerability

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Affected productsMicrosoft SQL Server 2019 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2019 for x64-based Systems (CU 32)
Fixed versions15.0.2190.7, 16.0.1200.5, 17.0.1135.8, 15.0.4490.9
Vendor guidance

Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.

Microsoft Security Response CenterCVE-2025-70873
HighCVSS 7.5

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

Mariner

Affected productsazl3 sqlite 3.44.0-2 on Azure Linux 3.0, Microsoft Visual Studio 2026 version 18.9, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Fixed versions3.44.0-3, 18.9.3, 17.14.40, 16.11.60
Vendor guidance

CBL-Mariner Releases Release Notes

Microsoft Security Response CenterCVE-2026-84358
Severity not listed

Chromium: CVE-2026-84358 Improper privilege management in Downloads

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.62
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-84332
Severity not listed

Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.62
Vendor guidance

Release Notes

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.