Security Briefs
Page 108 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 24, 2026, 6:00 AM UTC.
Showing page 108 (24 alerts) of 2651.
Fortinet FortiOS and FortiProxy Improper Authorization vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13382). An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Installer Spoofing Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-43890). Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. CISA remediation due date: 2021-12-29. If you need help checking exposure, call (864) 335-9223.
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44228). Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. CISA remediation due date: 2021-12-24. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Red Hat JBoss Application Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12149). The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. CISA remediation due date: 2022-06-10. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server-Side Request Forgery (SSRF) vulnerability
Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42321). An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Win32k Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40449). Unspecified vulnerability allows for an authenticated user to escalate privileges. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.
BQE BillQuick Web Suite SQL Injection Vulnerability
BQE BillQuick Web Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42258). BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server Path Traversal Vulnerability
Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42013). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server Path Traversal Vulnerability
Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41773). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Zoho ManageEngine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40539). Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft MSHTML Remote Code Execution Vulnerability
Microsoft MSHTML is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40444). Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Microsoft Open Management Infrastructure (OMI) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-38647). Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-36955). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-36942). Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
ForgeRock Access Management (AM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-35464). ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
SolarWinds Serv-U Remote Code Execution Vulnerability
SolarWinds Serv-U is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-35211). SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-34527). Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-34523). Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-34473). Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Security Feature Bypass Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-31207). Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-30116). Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Accellion FTA OS Command Injection Vulnerability
Accellion FTA is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27104). Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
Accellion FTA is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27103). Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.