Microsoft Security Response Center
The Microsoft Security Response Center (MSRC) publishes CVE-level security update information for Windows, Office, Azure, Exchange and the rest of the Microsoft portfolio, including whether a vulnerability was publicly disclosed or exploited before the fix shipped.
CSIRTS.com ingests Microsoft Security Response Center every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes CVE-level security update guide entries. Also available via RSS, JSON API and the MCP server.
Latest from Microsoft Security Response Center
CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
CVE-2026-77014: Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses
CVE-2026-75593: BuildKit: Malicious client can bypass destination directory validation on local sources upload
CVE-2026-74733: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
CVE-2026-74732: drm/amd/display: Check for tg ops in dce110_set_avmute
CVE-2026-74730: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
CVE-2026-74729: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
CVE-2026-74726: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
CVE-2026-74725: enic: fix tx_hang_reset use-after-free on device removal
CVE-2026-74724: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
CVE-2026-74723: btrfs: lzo: reject inline extents without valid headers
CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write()
CVE-2026-74720: bpf: Preserve pointer state for commuted arithmetic
CVE-2026-74719: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
CVE-2026-74718: devlink: fix net namespace reference leak in reload
CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error
CVE-2026-74715: bpf: Fix netns reference imbalance in conntrack kfuncs
CVE-2026-74714: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
CVE-2026-74713: vhost_iotlb: bound map allocation in add_range
CVE-2026-74711: hwmon: (pmbus) Fix type confusion in notification logic
CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation
CVE-2026-74704: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
CVE-2026-74701: net/openvswitch: check Ethernet header length in key_extract()
CVE-2026-74700: net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
Browse all 5,514 advisories from Microsoft Security Response Center →
Never miss a Microsoft Security Response Center advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.