Security Briefs
Page 101 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 101 (24 alerts) of 2651.
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22518). Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. CISA remediation due date: 2023-11-28. If you need help checking exposure, call (864) 335-9223.
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46604). Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. CISA remediation due date: 2023-11-23. If you need help checking exposure, call (864) 335-9223.
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration Utility is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46747). F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. CISA remediation due date: 2023-11-21. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4966). Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CISA remediation due date: 2023-11-08. If you need help checking exposure, call (864) 335-9223.
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Progress WS_FTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-40044). Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. CISA remediation due date: 2023-10-26. If you need help checking exposure, call (864) 335-9223.
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22515). Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. CISA remediation due date: 2023-10-13. If you need help checking exposure, call (864) 335-9223.
JetBrains TeamCity Authentication Bypass Vulnerability
JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-42793). JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CISA remediation due date: 2023-10-25. If you need help checking exposure, call (864) 335-9223.
Laravel Ignition File Upload Vulnerability
Laravel Ignition is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-3129). Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.
Zyxel EMG2926 Routers Command Injection Vulnerability
Zyxel EMG2926 Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-6884). Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Cisco Adaptive Security Appliance and Firepower Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-20269). Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. CISA remediation due date: 2023-10-04. If you need help checking exposure, call (864) 335-9223.
RARLAB WinRAR Code Execution Vulnerability
RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38831). RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. CISA remediation due date: 2023-09-14. If you need help checking exposure, call (864) 335-9223.
Ivanti Sentry Authentication Bypass Vulnerability
Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38035). Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. CISA remediation due date: 2023-09-12. If you need help checking exposure, call (864) 335-9223.
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27532). Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. CISA remediation due date: 2023-09-12. If you need help checking exposure, call (864) 335-9223.
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-35078). Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. CISA remediation due date: 2023-08-15. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-3519). Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. CISA remediation due date: 2023-08-09. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36884). Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. CISA remediation due date: 2023-08-29. If you need help checking exposure, call (864) 335-9223.
Netwrix Auditor Insecure Object Deserialization Vulnerability
Netwrix Auditor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-31199). Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling. CISA remediation due date: 2023-08-01. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Fortinet FortiOS and FortiProxy SSL-VPN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27997). Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests. CISA remediation due date: 2023-07-04. If you need help checking exposure, call (864) 335-9223.
Progress MOVEit Transfer SQL Injection Vulnerability
Progress MOVEit Transfer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-34362). Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. CISA remediation due date: 2023-06-23. If you need help checking exposure, call (864) 335-9223.
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-45046). Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. CISA remediation due date: 2023-05-22. If you need help checking exposure, call (864) 335-9223.
PaperCut MF/NG Improper Access Control Vulnerability
PaperCut MF/NG is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27350). PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. CISA remediation due date: 2023-05-12. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28252). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2023-05-02. If you need help checking exposure, call (864) 335-9223.
Veritas Backup Exec Agent Command Execution Vulnerability
Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27878). Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.
Veritas Backup Exec Agent Improper Authentication Vulnerability
Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27877). Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.