Vendor advisories

Microsoft Security Response Center

Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 5 hours ago Checked every 6 hours

4,355 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Microsoft Security Response CenterCVE-2026-71331
CriticalCVSS 8.1

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228.

Microsoft Security Response CenterCVE-2026-66802
CriticalCVSS 8.1

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5121000.

Microsoft Security Response CenterCVE-2026-49798
HighCVSS 9.3

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9020, 10.0.20348.5386, 10.0.19044.7548, 10.0.19045.7548
Vendor guidance

Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.

Microsoft Security Response CenterCVE-2026-70105
HighCVSS 6.5

Microsoft Word Information Disclosure Vulnerability

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Fixed versionshttps://aka.ms/OfficeSecurityReleases, 16.112.26081010, 16.0.5565.1000
Vendor guidance

Click to Run Release Notes Install KB5002901.

Microsoft Security Response CenterCVE-2026-62754
HighCVSS 7.8

Windows Kerberos Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5121000. Install KB5120418. Install KB5120386. Install ...

Microsoft Security Response CenterCVE-2026-65795
HighCVSS 6.7

Windows DNS Elevation of Privilege Vulnerability

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418.

Microsoft Security Response CenterCVE-2026-61363
HighCVSS 7.5

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-65786
HighCVSS 7.8

Desktop Window Manager Elevation of Privilege Vulnerability

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418.

Microsoft Security Response CenterCVE-2026-62755
HighCVSS 7.8

Windows DHCP Client Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...

Microsoft Security Response CenterCVE-2026-62703
HighCVSS 5.5

Windows DWM Core Library Information Disclosure Vulnerability

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.19044.7663
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.

Microsoft Security Response CenterCVE-2026-69414
HighCVSS 7.8

Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in t...

Affected productsMicrosoft Malware Protection Engine
Microsoft Security Response CenterCVE-2026-65675
HighCVSS 7.1

CoPilot Chat Security Feature Bypass Vulnerability

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

Affected productsMicrosoft Visual Studio Code CoPilot Chat Extension
Fixed versions2026.3.1
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-62705
HighCVSS 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

Affected productsWindows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems
Fixed versions10.0.26200.9168, 10.0.26200.9106, 10.0.26100.9168, 10.0.26100.9106
Vendor guidance

Install KB5121003. Install KB5120994. Install KB5121000.

Microsoft Security Response CenterCVE-2026-70338
HighCVSS 7.8

Microsoft PowerShell Security Feature Bypass Vulnerability

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Affected productsPowerShell 7.4, PowerShell 7.5, PowerShell 7.6
Fixed versions7.4.19.0, 7.5.10.0, 7.6.5
Vendor guidance

See the Microsoft Security Update Guide for the update that applies to your product.

Microsoft Security Response CenterCVE-2026-65791
CriticalCVSS 9.8

Windows iSCSI Target Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

Affected productsWindows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation)
Fixed versions10.0.17763.9121, 10.0.20348.5499, 10.0.20348.5440, 10.0.26100.33296
Vendor guidance

Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.

Microsoft Security Response CenterCVE-2026-66807
CriticalCVSS 7.8

Microsoft Office Graphics Component Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected productsMicrosoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office 2019 for 64-bit editions
Fixed versionshttps://aka.ms/OfficeSecurityReleases, 16.112.26081010
Vendor guidance

Click to Run Release Notes

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.