Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 3 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-70337
HighCVSS 8.8

Microsoft PowerShell Remote Code Execution Vulnerability

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

Affected productsPowerShell 7.5, PowerShell 7.4, PowerShell 7.6
Fixed versions7.5.10.0, 7.4.19.0, 7.6.5
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-65813
HighCVSS 6.5

Microsoft Exchange Server Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Affected productsMicrosoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14
Fixed versions15.02.2562.046, 15.01.2507.072, 15.02.1748.049, 15.02.1544.044
Vendor guidance

Install KB5121573. Install KB5121576. Install KB5121574. Install KB5121575.

Microsoft Security Response CenterCVE-2026-79289
Severity not listed

Chromium: CVE-2026-79289 Improper control of a resource through its lifetime in Workers

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.53
Vendor guidance

Release Notes

Microsoft Security Response CenterCVE-2026-79276
Severity not listed

Chromium: CVE-2026-79276 Improper privilege management in FileSystem

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.

Affected productsMicrosoft Edge (Chromium-based)
Fixed versions152.0.4191.53
Vendor guidance

Release Notes

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.