Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 2 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-54874
HighCVSS 7.5

Excessive Memory Use Buffering DTLS Records for a Future Epoch

Mariner

Affected productsazl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 qemu 9.1.0-11 on Azure Linux 3.0, azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-14456
HighCVSS 7.5

Unbounded Memory Growth in QUIC Server Incoming Channel Queue

Mariner

Affected productsazl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 rust 1.75.0-30 on Azure Linux 3.0, azl3 rust 1.90.0-10 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-63075
HighCVSS 7.5

QUIC ACK-only Packet Retention Can Cause Memory Exhaustion

Mariner

Affected productsazl3 rust 1.75.0-30 on Azure Linux 3.0, azl3 rust 1.90.0-10 on Azure Linux 3.0, azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-63072
HighCVSS 7.5

Heap Buffer Overflow in CMS Key Unwrapping

Mariner

Affected productsazl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 openssl 3.3.7-4 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-63074
MediumCVSS 5.9

CMP Indefinite Cache Growth of ExtraCerts

Mariner

Affected productsazl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 openssl 3.3.7-4 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-63073
CriticalCVSS 9.8

Untrusted Sender DN Used as Format String in CMP Response Validation

Mariner

Affected productsazl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 rust 1.75.0-30 on Azure Linux 3.0, azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 openssl 3.3.7-4 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-63076
HighCVSS 7.5

Invalid Pointer Dereference in CMP Server via Crafted protectionAlg

Mariner

Affected productsazl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0, azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 openssl 3.3.7-4 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-58612
HighCVSS 7.4

PowerShell Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

Affected productsPowerShell 7.5, PowerShell 7.4, PowerShell 7.6
Fixed versions7.5.10.0, 7.4.19.0, 7.6.5
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.