Vendor advisories
60 alerts in this category.
Vendor-issued security advisories — the official statements from product vendors about vulnerabilities affecting their software, including patch timelines, workarounds, and detection guidance.
Chrome Stable for iOS Update
Google Chrome Releases published an advisory on "Chrome Stable for iOS Update". Topic areas: google, chrome, browser, patch. Published August 4, 2026. See the original source linked under References f
GoogleChrome Beta for Desktop Update
Google Chrome Releases published an advisory on "Chrome Beta for Desktop Update". Topic areas: google, chrome, browser, patch. Published August 3, 2026. See the original source linked under References
GoogleDSA-6410-1 libssh - security update
https://security-tracker.debian.org/tracker/DSA-6410-1
DebianDSA-6409-1 libgd2 - security update
https://security-tracker.debian.org/tracker/DSA-6409-1
DebianDSA-6405-1 linux - security update
https://security-tracker.debian.org/tracker/DSA-6405-1
LinuxChrome Beta for iOS Update
Google Chrome Releases published an advisory on "Chrome Beta for iOS Update". Topic areas: google, chrome, browser, patch. Published July 30, 2026. See the original source linked under References for
GoogleChrome Dev for Desktop Update
Google Chrome Releases published an advisory on "Chrome Dev for Desktop Update". Topic areas: google, chrome, browser, patch. Published July 31, 2026. See the original source linked under References f
GoogleChrome Beta for Android Update
Google Chrome Releases published an advisory on "Chrome Beta for Android Update". Topic areas: google, chrome, browser, patch. Published July 30, 2026. See the original source linked under References
GoogleChrome Beta for Desktop Update
Google Chrome Releases published an advisory on "Chrome Beta for Desktop Update". Topic areas: google, chrome, browser, patch. Published July 30, 2026. See the original source linked under References
GoogleUSN-8624-1: Sinatra vulnerability
It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of s
USN-8625-1: OpenSSL vulnerability
It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to cons
OpenSSLDSA-6404-1 expat - security update
https://security-tracker.debian.org/tracker/DSA-6404-1
DebianStable Channel Update for Desktop
Google Chrome Releases published an advisory on "Stable Channel Update for Desktop". Topic areas: google, chrome, browser, patch. Published July 29, 2026. See the original source linked under Referenc
GoogleChrome for Android Update
Google Chrome Releases published an advisory on "Chrome for Android Update". Topic areas: google, chrome, browser, patch. Published July 29, 2026. See the original source linked under References for t
GoogleUSN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this
LinuxCVE-2026-43503Chrome Stable for iOS Update
Google Chrome Releases published an advisory on "Chrome Stable for iOS Update". Topic areas: google, chrome, browser, patch. Published July 28, 2026. See the original source linked under References fo
GoogleExtended Stable Updates for Desktop
Google Chrome Releases published an advisory on "Extended Stable Updates for Desktop". Topic areas: google, chrome, browser, patch. Published July 28, 2026. See the original source linked under Refere
GoogleUSN-8561-2: FreeRDP regression
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the in
DSA-6401-1 samba - security update
https://security-tracker.debian.org/tracker/DSA-6401-1
DebianUSN-8621-1: Samba vulnerabilities
It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by trigg
CVE-2026-15779USN-8616-1: Linux kernel (IBM) vulnerabilities
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP sub
LinuxCVE-2026-43284USN-8547-2: Linux kernel (Azure FIPS) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architectur
LinuxCVE-2022-48816USN-8617-1: Linux kernel (KVM) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this
LinuxCVE-2026-43503USN-8615-1: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this
LinuxCVE-2026-43503USN-8613-1: FreeIPMI vulnerabilities
Zhihan Zheng discovered that FreeIPMI had several buffer overflow vulnerabilities in ipmi-oem response message handling. A local attacker with control a malicious IPMI device or simulator could possib
CVE-2026-33554USN-8611-1: GNU C Library vulnerabilities
It was discovered that the GNU C Library iconv function incorrectly handled certain IBM character sets. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-4046) It was d
UbuntuCVE-2026-4046USN-8612-1: Roc Toolkit vulnerability
It was discovered that Roc Toolkit incorrectly handled WAV files with a malformed "smpl" chunk. An attacker could use this issue to cause Roc Toolkit to crash, resulting in a denial of service, or pos
Chrome Dev for Desktop Update
Google Chrome Releases published an advisory on "Chrome Dev for Desktop Update". Topic areas: google, chrome, browser, patch. Published July 24, 2026. See the original source linked under References f
GoogleCVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Microsoft Security Response Center published an advisory on "CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare". Topic areas: microsoft, windows, azure, patch. Published July 24, 202
CVE-2026-59677CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Microsoft Security Response Center published an advisory on "CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK". Topic areas: microsoft, windows, azure, patch. Published July 24,
CVE-2026-64600CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Microsoft Security Response Center published an advisory on "CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare". Topic areas: microsoft, windows, azure, patch. Published July 24
CVE-2026-59676CVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS
Microsoft Security Response Center published an advisory on "CVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS". Topic areas: microsoft, windows, azure, patch. Published Jul
CVE-2026-62389CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Microsoft Security Response Center published an advisory on "CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and
CVE-2026-26081CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length
Microsoft Security Response Center published an advisory on "CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length". Topic areas: microsoft, windows, azure, patch. Published July 22
CVE-2026-64191CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
Microsoft Security Response Center published an advisory on "CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name". Topic areas: microsoft, windows
CVE-2026-56416CVE-2026-53383 ksmbd: reject non-VALID session in compound request branch
Microsoft Security Response Center published an advisory on "CVE-2026-53383 ksmbd: reject non-VALID session in compound request branch". Topic areas: microsoft, windows, azure, patch. Published July 2
CVE-2026-53383CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
Microsoft Security Response Center published an advisory on "CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service". Topic areas: micros
CVE-2026-59885CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
MicrosoftCVE-2026-50517CVE-2026-63798 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
Microsoft Security Response Center published an advisory on "CVE-2026-63798 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove". Topic areas: microsoft, windows, azure, p
CVE-2026-63798CVE-2026-53400 i2c: core: fix adapter registration race
Microsoft Security Response Center published an advisory on "CVE-2026-53400 i2c: core: fix adapter registration race". Topic areas: microsoft, windows, azure, patch. Published July 20, 2026. See the o
CVE-2026-53400CVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
Microsoft Security Response Center published an advisory on "CVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink". Topic areas: microsoft, windows, azure, patch. Publi
CVE-2026-63829CVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritance
Microsoft Security Response Center published an advisory on "CVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritance". Topic areas: microsoft, windows, azure, patch. Pu
CVE-2026-64138CVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() access
Microsoft Security Response Center published an advisory on "CVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() access". Topic areas: microsoft, windows, azure, patch. Published July 21,
CVE-2026-64036CVE-2026-64077 netfilter: ebtables: move to two-stage removal scheme
Microsoft Security Response Center published an advisory on "CVE-2026-64077 netfilter: ebtables: move to two-stage removal scheme". Topic areas: microsoft, windows, azure, patch. Published July 21, 20
CVE-2026-64077CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root
Microsoft Security Response Center published an advisory on "CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root". Topic areas: microsoft, windows, azure, pat
CVE-2026-15788CVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pages
Microsoft Security Response Center published an advisory on "CVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pages". Topic areas: microsoft, windows, azure, patch. Published July 21, 2026. See the
AMDCVE-2026-63879CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes
Microsoft Security Response Center published an advisory on "CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes". Topic areas: microsoft, windows, azure, patch. Published
CVE-2026-63825CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg
Microsoft Security Response Center published an advisory on "CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg". Topic areas: microsoft, windows, azure, patch. Published J
CVE-2026-63828CVE-2026-63872 esp: fix page frag reference leak on skb_to_sgvec failure
Microsoft Security Response Center published an advisory on "CVE-2026-63872 esp: fix page frag reference leak on skb_to_sgvec failure". Topic areas: microsoft, windows, azure, patch. Published July 20
CVE-2026-63872CVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
Microsoft Security Response Center published an advisory on "CVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()". Topic areas: microsoft, windows, azure, patch. Published July 20, 2
CVE-2026-63814CVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
Microsoft Security Response Center published an advisory on "CVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()". Topic areas: microsoft, windows, azure, patch
CVE-2026-63962CVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cache
Microsoft Security Response Center published an advisory on "CVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cache". Topic areas: microsoft, windows, azure, patch. Published Jul
CVE-2026-64133CVE-2026-53399 nfsd: release layout stid on setlease failure
Microsoft Security Response Center published an advisory on "CVE-2026-53399 nfsd: release layout stid on setlease failure". Topic areas: microsoft, windows, azure, patch. Published July 20, 2026. See
CVE-2026-53399CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
MicrosoftCVE-2026-56165CVE-2026-63833 ntfs3: reject direct userspace writes to reserved $LX* xattrs
Microsoft Security Response Center published an advisory on "CVE-2026-63833 ntfs3: reject direct userspace writes to reserved $LX* xattrs". Topic areas: microsoft, windows, azure, patch. Published Jul
CVE-2026-63833CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted = SQL operators on text
Microsoft Security Response Center published an advisory on "CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted = SQL operators on text". Topic areas: microsoft, wind
CVE-2026-15043CVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handling
Microsoft Security Response Center published an advisory on "CVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handling". Topic areas: microsoft, windows, azure, patch. Published
CVE-2026-64060CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
Microsoft Security Response Center published an advisory on "CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak". Topic areas: microsof
CVE-2026-15713CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts
Microsoft Security Response Center published an advisory on "CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts". Topic areas: microsoft, windows, azure, patch. Published July 23, 2
CVE-2026-50045CVE-2026-63835 batman-adv: v: prevent OGM aggregation on disabled hardif
Microsoft Security Response Center published an advisory on "CVE-2026-63835 batman-adv: v: prevent OGM aggregation on disabled hardif". Topic areas: microsoft, windows, azure, patch. Published July 20
CVE-2026-63835
Get alerts that match YOUR environment
This page shows everything in the category. Vulnios narrows it down to alerts that affect your actual asset inventory — only the CVEs you need to act on.
Start a free scan