Microsoft Security Response Center
The Microsoft Security Response Center (MSRC) publishes CVE-level security update information for Windows, Office, Azure, Exchange and the rest of the Microsoft portfolio, including whether a vulnerability was publicly disclosed or exploited before the fix shipped.
CSIRTS.com ingests Microsoft Security Response Center every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes CVE-level security update guide entries. Also available via RSS, JSON API and the MCP server.
Latest from Microsoft Security Response Center
CVE-2026-75538: A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
CVE-2026-74994: inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
CVE-2026-74835: inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
CVE-2026-73812: inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
CVE-2026-73276: inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
CVE-2026-73270: httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
CVE-2026-72649: Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
CVE-2026-71562: httpc does not bound server-supplied numeric header values before integer conversion
CVE-2026-71380: httpd applies no timeout while receiving a request body, parking a worker on a stalled client
CVE-2026-70409: eldap does not bound the port component of a referral URL before integer conversion
CVE-2026-69664: httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
CVE-2026-66835: httpd mod_auth directory protection bypassed by a doubled slash in the request path
CVE-2026-66357: inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
CVE-2026-59696: uri_string does not bound the port component of a URI before integer conversion
CVE-2026-56143: Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
CVE-2026-55951: httpc memory exhaustion via unbounded response header accumulation
CVE-2026-18743: Popt-devel: popt-static: short realloc in poptconfigfiletostring
CVE-2026-14957: FIPS mode assertion failure via malicious CERT payload
CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
CVE-2026-13732: Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf
CVE-2026-82417: qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
CVE-2026-82327: Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data
CVE-2026-82254: gitoxide before 0.69.0 Denial of Service via gix-pack
CVE-2026-82253: gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass
Browse all 5,984 advisories from Microsoft Security Response Center →
Never miss a Microsoft Security Response Center advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.