Vendor advisories

Security advisories from the vendors you use.

Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.

9Vendor sources
4,726Advisories collected
2,720Published or updated in 30 days
2,115Marked critical or high
Coverage

Connected directly to official vendor sources

The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.

4,726 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
AWS Security BulletinsCVE-2026-16796
Severity not listed

CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that ins...

AWS Security BulletinsCVE-2026-16756
Severity not listed

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powerin...

AWS Security BulletinsCVE-2026-18655
Severity not listed

CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection

Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazo...

AWS Security Bulletins
Severity not listed

Unanchored ACCOUNT_ID webhook filters for CodeBuild

Bulletin ID: 2026-002-AWS Scope: AWS Content Type: Informational Publication Date: 2026/01/15 07:03 AM PST Description: A security research team identified a configuration issue affecting the following AWS-managed open source GitHub repositories that could have resulted in the...

AWS Security Bulletins
Severity not listed

Ongoing updates on Copy.fail and variants

Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the copy.fail or DirtyFrag cl...

Vendor guidance

This bulletin will be updated as more information becomes available.

Ubuntu Security NoticesUSN-8716-2
Severity not listed

USN-8716-2: FFmpeg vulnerabilities

USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possi...

Vendor guidance

USN-8716-1 fixed several vulnerabilities in FFmpeg.

Cisco Security Advisoriescisco-sa-onprem-fmc-authbypass-5JPp45V2
Critical

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Palo Alto Networks Security AdvisoriesPAN-SA-2026-0012
CriticalCVSS 9.4

PAN-SA-2026-0012: Chromium: Monthly Vulnerability Update (September 2026)

Palo Alto Networks incorporated the following Chromium security fixes into our products: * https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html

Affected productsPrisma Browser
Fixed versionsPrisma Browser >= 152.8.4.76
Vendor guidance

CVE PRISMA BROWSER CVE-2026-13774 150.41.2.115 CVE-2026-13775 150.41.2.115 CVE-2026-13776 150.41.2.115 CVE-2026-13777 150.41.2.115 CVE-2026-13778 150.41.2.115 CVE-2026-13779 150.41.2.115 CVE-2026-13780 150.41.2.115 CV...

Palo Alto Networks Security AdvisoriesCVE-2026-0310
CriticalCVSS 9.2

CVE-2026-0310: PAN-OS: Buffer Overflow Vulnerability via XML Processing

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls o...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.2
Fixed versionsCloud NGFW None on AWS*, None on Azure*, PAN-OS 12.2 >= 12.2.3, PAN-OS 12.1 >= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10, PAN-OS 11.2 >= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2...

Palo Alto Networks Security AdvisoriesCVE-2026-0309
HighCVSS 7.1

CVE-2026-0309: PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.2
Fixed versionsCloud NGFW All, PAN-OS 12.2 >= 12.2.3, PAN-OS 12.1 >= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10, PAN-OS 11.2 >= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2.3 or later. PAN-OS 12.1 12.1.8 through 12.1.9 Upgrade to 12.1.10 or later. 12.1.5 through 12.1.7-...

Palo Alto Networks Security AdvisoriesCVE-2026-0307
HighCVSS 8.5

CVE-2026-0307: GlobalProtect App: Local Privilege Escalation Vulnerabilities

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands...

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.0, GlobalProtect App 6.2
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h15 on macOS (ETA: 09/28), >= 6.3.3-h15 on Windows (ETA: 09/28), GlobalProtect App 6.0 >= 6.0.15 on Linux (ETA: 09/28), >= 6.0.15 on macOS (ETA: 09/28), >= 6.0.15 on Windows (ETA: 10/29), GlobalProtect App 6.2 >= 6.2.8-h14 on macOS, >= 6.2.8-h14 on Windows, GlobalProtect App All on iOS, All on Android, All on ChromeOS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.2/6.3 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. Global...

Palo Alto Networks Security AdvisoriesCVE-2026-0306
HighCVSS 8.4

CVE-2026-0306: Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and...

Affected productsPrisma Access Agent, Prisma Access Agent 0
Fixed versionsPrisma Access Agent 0 >= 26.2 on Windows, Prisma Access Agent All on Linux, All on macOS, All on iOS, All on Android, All on ChromeOS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Windows 24.0 through 26.2 Upgrade to 26.2 or later. Prisma Access Agent on Linux No action needed. Prisma Access Agent on macOS No action needed. Prisma ...

Palo Alto Networks Security AdvisoriesCVE-2026-0304
HighCVSS 7.5

CVE-2026-0304: Cortex XDR Broker VM: Privilege Escalation Vulnerability

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

Affected productsCortex XDR Broker VM, Cortex XDR Broker VM 20.0.96
Fixed versionsCortex XDR Broker VM 20.0.96 >= 32.0.52
Vendor guidance

This issue is fixed in Cortex XDR Broker VM 32.0.52, and all later Cortex XDR Broker VM versions. * If automatic upgrades are enabled for Broker VM, then no action is required at this time. * If automatic upgrades are...

Palo Alto Networks Security AdvisoriesCVE-2026-0308
MediumCVSS 4.8

CVE-2026-0308: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series fir...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.2
Fixed versionsCloud NGFW All, PAN-OS 12.2 All, PAN-OS 12.1 >= 12.1.10, PAN-OS 11.2 >= 11.2.13-h2
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.2 No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-...

Palo Alto Networks Security AdvisoriesCVE-2026-0305
MediumCVSS 6.8

CVE-2026-0305: Prisma Access Agent: Information Disclosure Vulnerability on Linux

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.

Affected productsPrisma Access Agent, Prisma Access Agent 24.0
Fixed versionsPrisma Access Agent 24.0 >= 26.3 on Linux, Prisma Access Agent All on macOS, All on Windows, All on iOS, All on Android, All on ChromeOS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Linux 25.7 through 26.2.2 Upgrade to 26.3 or later. Prisma Access Agent on macOS No action needed. Prisma Access Agent on Windows No action needed. Prism...

Palo Alto Networks Security AdvisoriesCVE-2026-0303
MediumCVSS 6.3

CVE-2026-0303: Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

Affected productsCheckov by Prisma Cloud, Checkov by Prisma Cloud 3.2.0
Fixed versionsCheckov by Prisma Cloud 3.2.0 >= 3.2.532
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.531 Upgrade to 3.2.532or later. Checkov integration in Prisma Cloud is upgraded automatically when new versions become available.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.