Skip to main content

Security Briefs

Page 118 of 165.

Alerts tracked

3940

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 8, 2026, 6:01 AM UTC.

Showing page 118 (24 alerts) of 3940.

Microsoft MSRC

CVE-2026-13026

Use after free in Digital Credentials in Microsoft Edge vulnerability

Use after free in Digital Credentials in Microsoft Edge vulnerability (CVE-2026-13026) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13025

Insufficient validation of untrusted input in DevTools in Microsoft Edge vulnerability

Insufficient validation of untrusted input in DevTools in Microsoft Edge vulnerability (CVE-2026-13025) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13024

Insufficient validation of untrusted input in Navigation in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Navigation in Microsoft Edge vulnerability (CVE-2026-13024) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13023

Uninitialized Use in GPU in Microsoft Edge vulnerability

Uninitialized Use in GPU in Microsoft Edge vulnerability (CVE-2026-13023) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13022

Inappropriate implementation in Autofill in Microsoft Edge vulnerability

Inappropriate implementation in Autofill in Microsoft Edge vulnerability (CVE-2026-13022) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13021

Inappropriate implementation in DeviceBoundSessionCredentials in Microsoft Edge vulnerability

Inappropriate implementation in DeviceBoundSessionCredentials in Microsoft Edge vulnerability (CVE-2026-13021) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Industry news

Russian Intelligence Services Continue to Target Commercial Messaging Applications

Russian Intelligence Services Continue to Target Commercial Messaging Applications — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

  • Vendor:FBI IC3
Microsoft MSRC

CVE-2026-45930

net: mctp: ensure our nlmsg responses are initialised

net net: mctp: ensure our nlmsg responses are initialised (CVE-2026-45930) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41086

Azure Portal Elevation of Privilege Vulnerability

Azure Portal Elevation of Privilege Vulnerability (CVE-2026-41086) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20230). Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. CISA remediation due date: 2026-06-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-12569

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-12569). PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. CISA remediation due date: 2026-06-28. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45504

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-45504) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42915

Microsoft Windows VMSwitch Denial of Service vulnerability

Microsoft Windows VMSwitch Denial of Service vulnerability (CVE-2026-42915) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-34910

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34910). Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection. CISA remediation due date: 2026-06-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-34909

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34909). Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account. CISA remediation due date: 2026-06-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-34908

Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti UniFi OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34908). Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system. CISA remediation due date: 2026-06-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-67038

Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-67038). Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. CISA remediation due date: 2026-06-26. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-45649

Office for Android Spoofing vulnerability

Office for Android Spoofing vulnerability (CVE-2026-45649) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45645

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-45645) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45643

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-45643) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45486

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-45486) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45485

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-45485) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45475

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-45475) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45474

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-45474) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.