Skip to main content

Security Briefs

Page 102 of 165.

Alerts tracked

3940

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 8, 2026, 6:01 AM UTC.

Showing page 102 (24 alerts) of 3940.

Actively exploited (KEV)

CVE-2026-48939

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda iCagenda is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48939). iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. CISA remediation due date: 2026-07-13. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-8932

conn reuse vulnerability

conn reuse vulnerability (CVE-2026-8932) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59999

sshd in OpenSSH before 10.4 vulnerability

In In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. (CVE-2026-59999) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-47241

Net::IMAP: Denial of Service via incomplete raw argument validation

Net Net::IMAP: Denial of Service via incomplete raw argument validation (CVE-2026-47241) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-46331

net/sched: fix pedit partial COW leading to page cache corruption

net net/sched: fix pedit partial COW leading to page cache corruption (CVE-2026-46331) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-46054

selinux: fix overlayfs mmap() and mprotect() access checks vulnerability

selinux: fix overlayfs mmap() and mprotect() access checks vulnerability (CVE-2026-46054) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58525

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-58525) was added to Microsoft’s security update guidance. Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50656

Microsoft Defender Elevation of Privilege vulnerability

Microsoft Defender Elevation of Privilege vulnerability (CVE-2026-50656) was added to Microsoft’s security update guidance. Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656. Please see the FAQ for more information on how to check if the new version has been installed. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-56290

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-56290). Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-55255

Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-55255). Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-48908

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48908). JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-48282

Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48282). Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. CISA remediation due date: 2026-07-10. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-53223

net: guard timestamp cmsgs to real error queue skbs

net net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58597

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58597) was added to Microsoft’s security update guidance. Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58524

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58524) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58523

Microsoft Edge for Android Security Feature Bypass vulnerability

Microsoft Edge for Android Security Feature Bypass vulnerability (CVE-2026-58523) was added to Microsoft’s security update guidance. Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58522

Microsoft Edge for Android Information Disclosure vulnerability

Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58522) was added to Microsoft’s security update guidance. Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58300

Microsoft Edge for Android Information Disclosure vulnerability

Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58300) was added to Microsoft’s security update guidance. Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58299

Microsoft Edge for Android Remote Code Execution vulnerability

Microsoft Edge for Android Remote Code Execution vulnerability (CVE-2026-58299) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58298

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58298) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58297

Microsoft Edge for Android Information Disclosure vulnerability

Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58297) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58296

Microsoft Edge for Android Information Disclosure vulnerability

Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58296) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58295

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-58295) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58294

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-58294) was added to Microsoft’s security update guidance. Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.