Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,726 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that ins...
CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:20 PM PDT Description: FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in th...
CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool
Bulletin ID: 2026-056-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 11:30 AM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools fo...
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powerin...
CVE-2026-13769 - Insecure file permissions in AWS CLI
Bulletin ID: 2026-049-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in ...
CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT Description: jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incomp...
CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
Bulletin ID: 2026-068-AWS Publication Date: 07/31/2026 11:00 AM PDT Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazo...
CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
Bulletin ID: 2026-069-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 12:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK,...
Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Unanchored ACCOUNT_ID webhook filters for CodeBuild
Bulletin ID: 2026-002-AWS Scope: AWS Content Type: Informational Publication Date: 2026/01/15 07:03 AM PST Description: A security research team identified a configuration issue affecting the following AWS-managed open source GitHub repositories that could have resulted in the...
Ongoing updates on Copy.fail and variants
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the copy.fail or DirtyFrag cl...
This bulletin will be updated as more information becomes available.
USN-8716-2: FFmpeg vulnerabilities
USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possi...
USN-8716-1 fixed several vulnerabilities in FFmpeg.
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This...
Cisco has released software updates that address this vulnerability.
PAN-SA-2026-0012: Chromium: Monthly Vulnerability Update (September 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: * https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html
CVE PRISMA BROWSER CVE-2026-13774 150.41.2.115 CVE-2026-13775 150.41.2.115 CVE-2026-13776 150.41.2.115 CVE-2026-13777 150.41.2.115 CVE-2026-13778 150.41.2.115 CVE-2026-13779 150.41.2.115 CVE-2026-13780 150.41.2.115 CV...
CVE-2026-0310: PAN-OS: Buffer Overflow Vulnerability via XML Processing
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls o...
VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2...
CVE-2026-0309: PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device...
VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2.3 or later. PAN-OS 12.1 12.1.8 through 12.1.9 Upgrade to 12.1.10 or later. 12.1.5 through 12.1.7-...
CVE-2026-0307: GlobalProtect App: Local Privilege Escalation Vulnerabilities
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands...
VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.2/6.3 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. Global...
CVE-2026-0306: Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and...
VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Windows 24.0 through 26.2 Upgrade to 26.2 or later. Prisma Access Agent on Linux No action needed. Prisma Access Agent on macOS No action needed. Prisma ...
CVE-2026-0304: Cortex XDR Broker VM: Privilege Escalation Vulnerability
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
This issue is fixed in Cortex XDR Broker VM 32.0.52, and all later Cortex XDR Broker VM versions. * If automatic upgrades are enabled for Broker VM, then no action is required at this time. * If automatic upgrades are...
CVE-2026-0308: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series fir...
VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.2 No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-...
CVE-2026-0305: Prisma Access Agent: Information Disclosure Vulnerability on Linux
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.
VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Linux 25.7 through 26.2.2 Upgrade to 26.3 or later. Prisma Access Agent on macOS No action needed. Prisma Access Agent on Windows No action needed. Prism...
CVE-2026-0303: Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
VERSION MINOR VERSION SUGGESTED SOLUTION Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.531 Upgrade to 3.2.532or later. Checkov integration in Prisma Cloud is upgraded automatically when new versions become available.
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.