Vendor advisories
60 alerts in this category.
Vendor-issued security advisories — the official statements from product vendors about vulnerabilities affecting their software, including patch timelines, workarounds, and detection guidance.
DSA-6485-1 tryton-server - security update
https://security-tracker.debian.org/tracker/DSA-6485-1
DebianDSA-6483-1 thunderbird - security update
https://security-tracker.debian.org/tracker/DSA-6483-1
DebianChrome Dev for Android Update
Google Chrome Releases published an advisory on "Chrome Dev for Android Update". Topic areas: google, chrome, browser, patch. Published September 4, 2026. See the original source linked under Referenc
GoogleChrome Dev for Desktop Update
Google Chrome Releases published an advisory on "Chrome Dev for Desktop Update". Topic areas: google, chrome, browser, patch. Published September 4, 2026. See the original source linked under Referenc
GoogleUSN-8714-2: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system;
LinuxCVE-2026-53043USN-8725-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - NVIDIA Tegra memor
LinuxCVE-2022-50401Chromium: CVE-2026-84355 Incorrect authorization in Navigation
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84355Chromium: CVE-2026-84349 Use after free in Browser
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84349Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84332Chromium: CVE-2026-84328 Missing authorization in FileSystem
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84328Chromium: CVE-2026-84324 Use after free in Proxy
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84324Chromium: CVE-2026-84323 Missing authorization in FileSystem
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84323CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
AzureCVE-2026-70352Chromium: CVE-2026-84326 Uninitialized resource in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84326Chromium: CVE-2026-84350 Use after free in TabStrip
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84350Chromium: CVE-2026-84325 Improper input validation in DataTransfer
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84325Chromium: CVE-2026-84357 Improper input validation in Omnibox
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84357CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-80098Chromium: CVE-2026-84353 Use after free in Shared Tab Groups
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84353CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
AzureCVE-2026-69857Chromium: CVE-2026-84331 Incorrect authorization in Actor
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84331CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
MicrosoftCVE-2026-62916Chromium: CVE-2026-84347 Use after free in WebRTC
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84347CVE-2026-65818 Power Automate Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVE-2026-65818Chromium: CVE-2026-84348 Information leak in MediaCapture
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84348Chromium: CVE-2026-84351 Buffer overflow in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84351CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
MicrosoftCVE-2026-83711Chromium: CVE-2026-84327 Incorrect authorization in Autofill
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84327Chromium: CVE-2026-84358 Improper privilege management in Downloads
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84358Chromium: CVE-2026-84329 Confused deputy in CredentialProvider
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84329Chromium: CVE-2026-84335 Incorrect authorization in TabStrip
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84335CVE-2026-62906 Microsoft Discovery Studio Information Disclosure Vulnerability
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
MicrosoftCVE-2026-62906Chromium: CVE-2026-84359 Information leak in Skia
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84359CVE-2026-70178 Microsoft Fabric Elevation of Privilege Vulnerability
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
MicrosoftCVE-2026-70178Chromium: CVE-2026-84356 UI misrepresentation in FullScreen
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84356Chromium: CVE-2026-84334 Incorrect authorization in Chromoting
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84334Chromium: CVE-2026-84354 Incorrect authorization in FileSystem
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-84354Early Stable Update for Desktop
Google Chrome Releases published an advisory on "Early Stable Update for Desktop". Topic areas: google, chrome, browser, patch. Published September 3, 2026. See the original source linked under Refere
GoogleChrome for Android Update
Google Chrome Releases published an advisory on "Chrome for Android Update". Topic areas: google, chrome, browser, patch. Published September 3, 2026. See the original source linked under References f
GoogleDSA-6482-1 chromium - security update
https://security-tracker.debian.org/tracker/DSA-6482-1
DebianUSN-8724-1: rabbitmq-c vulnerabilities
It was discovered that the rabbitmq-c command-line tools only accepted credentials on the command line, making them visible to other local users through the process list. An attacker could possibly us
UbuntuCVE-2023-35789USN-8723-1: SPICE vdagent vulnerabilities
It was discovered that SPICE vdagent had an integer overflow in the buffer size calculation used when writing to the daemon socket. A malicious or compromised SPICE host could possibly use this issue
CVE-2026-57965USN-8722-1: libssh2 vulnerabilities
It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitra
CVE-2026-66032USN-8720-1: GnuPG vulnerability
It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could possibly use this issue to bypass message integrity ch
USN-8719-1: APR-util vulnerabilities
It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-202
UbuntuCVE-2025-49506USN-8718-1: SSSD vulnerability
It was discovered that SSSD did not properly validate authentication token lengths when processing PAM responder requests. A local attacker could possibly use this issue to cause SSSD to crash, result
USN-8717-1: Apache Tika vulnerability
It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to rea
ApacheUSN-8661-4: Linux kernel vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE
LinuxCVE-2020-24588USN-8715-1: Linux kernel (Oracle) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE
LinuxCVE-2020-24588USN-8714-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system;
LinuxCVE-2026-53043Chrome Beta for iOS Update
Google Chrome Releases published an advisory on "Chrome Beta for iOS Update". Topic areas: google, chrome, browser, patch. Published September 2, 2026. See the original source linked under References
GoogleChrome Beta for Android Update
Google Chrome Releases published an advisory on "Chrome Beta for Android Update". Topic areas: google, chrome, browser, patch. Published September 2, 2026. See the original source linked under Referen
GoogleChrome Beta for Desktop Update
Google Chrome Releases published an advisory on "Chrome Beta for Desktop Update". Topic areas: google, chrome, browser, patch. Published September 2, 2026. See the original source linked under Referen
GoogleUSN-8713-1: BioSig vulnerabilities
Mark Bereza and Lilith Wyatt discovered that BioSig incorrectly handled certain crafted input files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (
CVE-2026-22891Chrome for Android
Google Chrome Releases published an advisory on "Chrome for Android". Topic areas: google, chrome, browser, patch. Published September 1, 2026. See the original source linked under References for the
GoogleUSN-8710-1: libevent vulnerabilities
Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a use-after-free, resulting in a denial of service or a
UbuntuCVE-2026-63381USN-8709-1: ncurses vulnerability
It was discovered that ncurses incorrectly handled specially crafted terminfo database entries. A local attacker could possibly use this issue to cause applications using ncurses to crash, resulting i
USN-8711-1: Libgcrypt vulnerability
It was discovered that Libgcrypt had a timing-based side-channel flaw in its RSA implementation. A remote attacker could possibly use this issue to obtain sensitive information.
USN-8555-2: Ubuntu Advantage Tools (pro client) regression
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu 14.04 LTS only, it was discovered that some machines were unable to enable esm-infra-legacy due to a preemptive apt-helper check.
UbuntuCVE-2026-9494USN-8688-2: PAM vulnerability
USN-8688-1 fixed a vulnerability in PAM. This update provides the corresponding fix for PAM on Ubuntu 26.04 LTS. Original advisory details: Juthawong Naisanguansee discovered that PAM incorrectly clea
Ubuntu
Get alerts that match YOUR environment
This page shows everything in the category. Vulnios narrows it down to alerts that affect your actual asset inventory — only the CVEs you need to act on.
Start a free scan