Skip to main content

Security Briefs

Page 116 of 165.

Alerts tracked

3940

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 8, 2026, 6:01 AM UTC.

Showing page 116 (24 alerts) of 3940.

Microsoft MSRC

CVE-2026-13779

Use after free in Chromoting in Microsoft Edge vulnerability

Use after free in Chromoting in Microsoft Edge vulnerability (CVE-2026-13779) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13776

Type Confusion in Dawn in Microsoft Edge vulnerability

Type Confusion in Dawn in Microsoft Edge vulnerability (CVE-2026-13776) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13775

Use after free in GPU in Microsoft Edge vulnerability

Use after free in GPU in Microsoft Edge vulnerability (CVE-2026-13775) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13774

Use after free in Extensions in Microsoft Edge vulnerability

Use after free in Extensions in Microsoft Edge vulnerability (CVE-2026-13774) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57100

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability (CVE-2026-57100) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54998

Microsoft Exchange Online Elevation of Privilege vulnerability

Microsoft Exchange Online Elevation of Privilege vulnerability (CVE-2026-54998) was added to Microsoft’s security update guidance. Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50521

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-50521) was added to Microsoft’s security update guidance. Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41106

Microsoft 365 Copilot Elevation of Privilege vulnerability

Microsoft 365 Copilot Elevation of Privilege vulnerability (CVE-2026-41106) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-26145

Microsoft Azure Synapse Elevation of Privilege vulnerability

Microsoft Azure Synapse Elevation of Privilege vulnerability (CVE-2026-26145) was added to Microsoft’s security update guidance. Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-45659

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45659). Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. CISA remediation due date: 2026-07-04. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32208

Microsoft Entra ID Spoofing vulnerability

Microsoft Entra ID Spoofing vulnerability (CVE-2026-32208) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13595

Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

Util-linux Util-linux: util-linux: heap use-after-free in libblkid nested partition probing (CVE-2026-13595) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42910

Windows Hotpatch Monitoring Service Elevation of Privilege vulnerability

Windows Hotpatch Monitoring Service Elevation of Privilege vulnerability (CVE-2026-42910) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-48558

SimpleHelp Authentication Bypass Vulnerability

SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48558). SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. CISA remediation due date: 2026-07-02. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56132

libexpat before 2.8.2 vulnerability

In In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. (CVE-2026-56132) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53297

net: mana: Guard mana_remove against double invocation

net net: mana: Guard mana_remove against double invocation (CVE-2026-53297) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53292

net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind

net net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind (CVE-2026-53292) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53274

net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS

net net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (CVE-2026-53274) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53264

net/sched: act_api: use RCU with deferred freeing for action lifecycle

net net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53247

net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown

net net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown (CVE-2026-53247) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53245

net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr

net net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (CVE-2026-53245) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53232

net: phy: clean the sfp upstream if phy probing fails

net net: phy: clean the sfp upstream if phy probing fails (CVE-2026-53232) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53230

net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list

net net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-53227

net: openvswitch: fix possible kfree_skb of ERR_PTR

net net: openvswitch: fix possible kfree_skb of ERR_PTR (CVE-2026-53227) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.