Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 3 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-43871
HighCVSS 7.5

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit

Mariner

Affected productsazl3 thrift 0.15.0-6 on Azure Linux 3.0, azl3 influxdb 2.7.5-19 on Azure Linux 3.0, azl3 kata-containers-cc 3.15.0.aks0-16 on Azure Linux 3.0, azl3 telegraf 1.31.0-27 on Azure Linux 3.0
Fixed versions0.24.0-1, 2.7.5-20, 19.0.4-12, 1.31.0-26
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-55969
HighCVSS 7.5

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()

Mariner

Affected productsazl3 thrift 0.15.0-6 on Azure Linux 3.0, azl3 telegraf 1.31.0-27 on Azure Linux 3.0, azl3 telegraf 1.31.0-28 on Azure Linux 3.0, azl3 influxdb 2.7.5-19 on Azure Linux 3.0
Fixed versions0.24.0-1, 2.7.5-20, 19.0.4-12
Vendor guidance

CBL-Mariner Releases

Microsoft Security Response CenterCVE-2026-48586
HighCVSS 7.5

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit

Mariner

Affected productsazl3 thrift 0.15.0-6 on Azure Linux 3.0, azl3 influxdb 2.7.5-19 on Azure Linux 3.0, azl3 kata-containers-cc 3.15.0.aks0-16 on Azure Linux 3.0, azl3 telegraf 1.31.0-27 on Azure Linux 3.0
Fixed versions0.24.0-1, 2.7.5-20, 1.31.0-28
Vendor guidance

CBL-Mariner Releases

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.