CISA known exploited vulnerabilities
Under attack. Patch these first.
Page 17 of 21
Alerts tracked
2627
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.
Showing page 17 (24 alerts) of 503 known-exploited alerts.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1064). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0841). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0543). A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8120). A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0101). A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-3309). A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Memory Corruption Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-2546). The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Adobe BlazeDS Information Disclosure Vulnerability
Adobe BlazeDS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3960). Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. CISA remediation due date: 2022-09-07. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41379). Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-03-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8581). A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. CISA remediation due date: 2022-03-17. If you need help checking exposure, call (864) 335-9223.
Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-1019). Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0099). A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-7645). Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-1701). An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-4681). The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1723). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-0507). An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Adobe Reader and Acrobat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0188). Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Adobe Reader and Acrobat Input Validation Vulnerability
Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-2992). Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaborate Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-24682). Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. CISA remediation due date: 2022-03-11. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Type Confusion Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0752). A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8174). A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.
WinRAR Absolute Path Traversal Vulnerability
RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-20250). WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.
Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-15982). Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.