Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,737 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Chromium: CVE-2026-84329 Confused deputy in CredentialProvider
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
Chromium: CVE-2026-84328 Missing authorization in FileSystem
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
Chromium: CVE-2026-84327 Incorrect authorization in Autofill
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
Chromium: CVE-2026-84326 Uninitialized resource in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
Chromium: CVE-2026-84325 Improper input validation in DataTransfer
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
Chromium: CVE-2026-84324 Use after free in Proxy
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
Chromium: CVE-2026-84323 Missing authorization in FileSystem
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Release Notes
XenServer Security Update for Multiple Issues
Several issues have been identified that affect XenServer 8.4 and XenServer 9. Collectively, these issues may allow a malicious privileged user in a guest VM to compromise or crash the host.
We have pushed updates to both the Early Access and Normal update channels of each of XenServer 8.4 and XenServer 9. We recommend that customers update to the latest version from their chosen channel following the ins...
rpcapd memory leak in libpcap before 1.10.7
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
wolfSSL CA-cache hit overrides callback
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
JWT used for authentication in web GUI signed with static key
CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00
Improper Authentication of FortiPAM Server
CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious websit...
ZTNA Portal Improper Certificate Validation
CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backe...
Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00
Workflow session email approval process bypass
CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00
Uncontrolled Resource Consumption in SNMP
CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00
Open Redirect on FortiSIEM
CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.