CISA known exploited vulnerabilities
Under attack. Patch these first.
Page 4 of 23
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 5, 2026, 6:01 AM UTC.
Showing page 4 (24 alerts) of 545 known-exploited alerts.
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory Joomla Content Editor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48907). Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. CISA remediation due date: 2026-06-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
LiteSpeed cPanel Plugin is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-54420). LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. CISA remediation due date: 2026-06-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20262). Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. CISA remediation due date: 2026-06-29. If you need help checking exposure, call (864) 335-9223.
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-35273). Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. CISA remediation due date: 2026-06-15. If you need help checking exposure, call (864) 335-9223.
Ivanti Sentry OS Command Injection Vulnerability
Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-10520). Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. CISA remediation due date: 2026-06-14. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Arista Extensible Operating System is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-7473). Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. CISA remediation due date: 2026-06-23. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20245). Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. CISA remediation due date: 2026-06-23. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-11645). Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-06-23. If you need help checking exposure, call (864) 335-9223.
Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-50751). Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. CISA remediation due date: 2026-06-11. If you need help checking exposure, call (864) 335-9223.
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
SolarWinds Serv-U is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-28318). SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. CISA remediation due date: 2026-06-19. If you need help checking exposure, call (864) 335-9223.
Android Framework Integer Overflow Vulnerability
Android Framework is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-48595). Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. CISA remediation due date: 2026-06-05. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Improper Authentication Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-0492). Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. CISA remediation due date: 2026-06-05. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0257). Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. CISA remediation due date: 2026-06-01. If you need help checking exposure, call (864) 335-9223.
Nx Console Embedded Malicious Code Vulnerability
Nx Nx Console is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48027). Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. CISA remediation due date: 2026-06-10. If you need help checking exposure, call (864) 335-9223.
TanStack Unspecified Vulnerability
TanStack TanStack is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45321). TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. CISA remediation due date: 2026-06-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Denial of Service Vulnerability
Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45498). Microsoft Defender contains an unspecified vulnerability that allows for denial of service. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Link Following Vulnerability
Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-41091). Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0806). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0249). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3459). Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft DirectX NULL Byte Overwrite Vulnerability
Microsoft DirectX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-1537). Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4250). Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20182). Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. CISA remediation due date: 2026-05-17. If you need help checking exposure, call (864) 335-9223.
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-6973). Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. CISA remediation due date: 2026-05-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.