Skip to main content

Security Briefs

Page 101 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 101 (24 alerts) of 2651.

Actively exploited (KEV)Ransomware

CVE-2023-22518

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22518). Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. CISA remediation due date: 2023-11-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-46604

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46604). Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. CISA remediation due date: 2023-11-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-46747

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration Utility is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46747). F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. CISA remediation due date: 2023-11-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-4966

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4966). Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CISA remediation due date: 2023-11-08. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-40044

Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Progress WS_FTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-40044). Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. CISA remediation due date: 2023-10-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-22515

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22515). Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. CISA remediation due date: 2023-10-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-42793

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-42793). JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CISA remediation due date: 2023-10-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-3129

Laravel Ignition File Upload Vulnerability

Laravel Ignition is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-3129). Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-6884

Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-6884). Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-20269

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-20269). Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. CISA remediation due date: 2023-10-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-38831

RARLAB WinRAR Code Execution Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38831). RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. CISA remediation due date: 2023-09-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-38035

Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38035). Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. CISA remediation due date: 2023-09-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-27532

Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27532). Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. CISA remediation due date: 2023-09-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-35078

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-35078). Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. CISA remediation due date: 2023-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-3519

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-3519). Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. CISA remediation due date: 2023-08-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-36884

Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36884). Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. CISA remediation due date: 2023-08-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-31199

Netwrix Auditor Insecure Object Deserialization Vulnerability

Netwrix Auditor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-31199). Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling. CISA remediation due date: 2023-08-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-27997

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27997). Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests. CISA remediation due date: 2023-07-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-34362

Progress MOVEit Transfer SQL Injection Vulnerability

Progress MOVEit Transfer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-34362). Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. CISA remediation due date: 2023-06-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-45046

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-45046). Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. CISA remediation due date: 2023-05-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-27350

PaperCut MF/NG Improper Access Control Vulnerability

PaperCut MF/NG is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27350). PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. CISA remediation due date: 2023-05-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-28252

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28252). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2023-05-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27878

Veritas Backup Exec Agent Command Execution Vulnerability

Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27878). Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27877

Veritas Backup Exec Agent Improper Authentication Vulnerability

Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27877). Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.