Security Briefs
Page 10 of 21.
Alerts tracked
2625
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.
Showing page 10 (24 alerts) of 503.
Microsoft SharePoint Deserialization Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-38094). Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. CISA remediation due date: 2024-11-12. If you need help checking exposure, call (864) 335-9223.
Veeam Backup and Replication Deserialization Vulnerability
Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40711). Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. CISA remediation due date: 2024-11-07. If you need help checking exposure, call (864) 335-9223.
Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9680). Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30088). Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Microsoft SQL Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0618). Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. CISA remediation due date: 2024-10-09. If you need help checking exposure, call (864) 335-9223.
Progress WhatsUp Gold SQL Injection Vulnerability
Progress WhatsUp Gold is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-6670). Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. CISA remediation due date: 2024-10-07. If you need help checking exposure, call (864) 335-9223.
SonicWall SonicOS Improper Access Control Vulnerability
SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40766). SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-1000253). Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Jenkins Jenkins Command Line Interface (CLI) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23897). Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. CISA remediation due date: 2024-09-09. If you need help checking exposure, call (864) 335-9223.
VMware ESXi Authentication Bypass Vulnerability
VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-37085). VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. CISA remediation due date: 2024-08-20. If you need help checking exposure, call (864) 335-9223.
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Rejetto HTTP File Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23692). Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. CISA remediation due date: 2024-07-30. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-26169). Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. CISA remediation due date: 2024-07-04. If you need help checking exposure, call (864) 335-9223.
PHP-CGI OS Command Injection Vulnerability
PHP Group PHP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-4577). PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. CISA remediation due date: 2024-07-03. If you need help checking exposure, call (864) 335-9223.
Check Point Quantum Security Gateways Information Disclosure Vulnerability
Check Point Quantum Security Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-24919). Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Use-After-Free Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1086). Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
NextGen Healthcare Mirth Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-43208). NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. CISA remediation due date: 2024-06-10. If you need help checking exposure, call (864) 335-9223.
Microsoft DWM Core Library Privilege Escalation Vulnerability
Microsoft DWM Core Library is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30051). Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. CISA remediation due date: 2024-06-04. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Command Injection Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-3400). Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. CISA remediation due date: 2024-04-19. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Code Injection Vulnerability
Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24955). Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. CISA remediation due date: 2024-04-16. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet FortiClient EMS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-48788). Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. CISA remediation due date: 2024-04-15. If you need help checking exposure, call (864) 335-9223.
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44529). Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). CISA remediation due date: 2024-04-15. If you need help checking exposure, call (864) 335-9223.
JetBrains TeamCity Authentication Bypass Vulnerability
JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-27198). JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CISA remediation due date: 2024-03-28. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21338). Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. CISA remediation due date: 2024-03-25. If you need help checking exposure, call (864) 335-9223.
ConnectWise ScreenConnect Authentication Bypass Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1709). ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices. CISA remediation due date: 2024-02-29. If you need help checking exposure, call (864) 335-9223.