Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,737Advisories collected
2,716Published or updated in 30 days
2,119Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,737 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-84325
Severity not listed

Chromium: CVE-2026-84325 Improper input validation in DataTransfer

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.62
Vendor guidance

Release Notes

Citrix Security BulletinsCTX697038
High

XenServer Security Update for Multiple Issues

Several issues have been identified that affect XenServer 8.4 and XenServer 9. Collectively, these issues may allow a malicious privileged user in a guest VM to compromise or crash the host.

Affected productsXenServer, These issues affect both XenServer 8.4 and XenServer 9; versions of the XenServer Terraform provider versions before version 0.3.0 are affected by the Terraform issue.
Vendor guidance

We have pushed updates to both the Early Access and Normal update channels of each of XenServer 8.4 and XenServer 9. We recommend that customers update to the latest version from their chosen channel following the ins...

Microsoft Security Response CenterCVE-2026-86143
MediumCVSS 6.9

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

Mariner

Affected productsazl3 libxml2 2.11.5-10 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-86144
MediumCVSS 5.6

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

Mariner

Affected productsazl3 libxml2 2.11.5-10 on Azure Linux 3.0
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Fortinet PSIRT AdvisoriesFG-IR-26-168
CriticalCVSS 9.1

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious websit...

Affected productsFortiPAM
Fortinet PSIRT AdvisoriesFG-IR-26-174
HighCVSS 7.3

ZTNA Portal Improper Certificate Validation

CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backe...

Affected productsFortiOS, FortiProxy
Fortinet PSIRT AdvisoriesFG-IR-26-166
HighCVSS 8.9

Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Affected productsFortiSandbox, FortiSandbox Cloud
Fortinet PSIRT AdvisoriesFG-IR-26-172
MediumCVSS 5.9

Uncontrolled Resource Consumption in SNMP

CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00

Affected productsFortiAnalyzer
Fortinet PSIRT AdvisoriesFG-IR-26-169
LowCVSS 2.8

Open Redirect on FortiSIEM

CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00

Affected productsFortiSIEM
Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.