Security Briefs
Page 102 of 165.
Alerts tracked
3940
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 8, 2026, 6:01 AM UTC.
Showing page 102 (24 alerts) of 3940.
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda iCagenda is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48939). iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. CISA remediation due date: 2026-07-13. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
conn reuse vulnerability
conn reuse vulnerability (CVE-2026-8932) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
sshd in OpenSSH before 10.4 vulnerability
In In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. (CVE-2026-59999) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Net::IMAP: Denial of Service via incomplete raw argument validation
Net Net::IMAP: Denial of Service via incomplete raw argument validation (CVE-2026-47241) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/sched: fix pedit partial COW leading to page cache corruption
net net/sched: fix pedit partial COW leading to page cache corruption (CVE-2026-46331) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
selinux: fix overlayfs mmap() and mprotect() access checks vulnerability
selinux: fix overlayfs mmap() and mprotect() access checks vulnerability (CVE-2026-46054) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-58525) was added to Microsoft’s security update guidance. Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Elevation of Privilege vulnerability
Microsoft Defender Elevation of Privilege vulnerability (CVE-2026-50656) was added to Microsoft’s security update guidance. Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656. Please see the FAQ for more information on how to check if the new version has been installed. If you need help checking exposure, call (864) 335-9223.
Joomlack Page Builder Improper Access Control Vulnerability
Joomlack Page Builder is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-56290). Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-55255). Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48908). JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48282). Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. CISA remediation due date: 2026-07-10. If you need help checking exposure, call (864) 335-9223.
net: guard timestamp cmsgs to real error queue skbs
net net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58597) was added to Microsoft’s security update guidance. Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58524) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge for Android Security Feature Bypass vulnerability
Microsoft Edge for Android Security Feature Bypass vulnerability (CVE-2026-58523) was added to Microsoft’s security update guidance. Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge for Android Information Disclosure vulnerability
Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58522) was added to Microsoft’s security update guidance. Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge for Android Information Disclosure vulnerability
Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58300) was added to Microsoft’s security update guidance. Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge for Android Remote Code Execution vulnerability
Microsoft Edge for Android Remote Code Execution vulnerability (CVE-2026-58299) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58298) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge for Android Information Disclosure vulnerability
Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58297) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge for Android Information Disclosure vulnerability
Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58296) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-58295) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-58294) was added to Microsoft’s security update guidance. Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.