Security Briefs
Page 118 of 142.
Alerts tracked
3940
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 8, 2026, 6:01 AM UTC.
Showing page 118 (24 alerts) of 3385.
Dynamics 365 Elevation of Privilege vulnerability
Dynamics 365 Elevation of Privilege vulnerability (CVE-2026-47647) was added to Microsoft’s security update guidance. Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Dynamics 365 Customer Voice Spoofing vulnerability
Dynamics 365 Customer Voice Spoofing vulnerability (CVE-2026-47646) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft 365 Copilot's Business Chat Elevation of Privilege vulnerability
Microsoft 365 Copilot's Business Chat Elevation of Privilege vulnerability (CVE-2026-47645) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Cost Management Information Disclosure vulnerability
Microsoft Cost Management Information Disclosure vulnerability (CVE-2026-47633) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Azure Active Directory Elevation of Privilege vulnerability
Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-45480) was added to Microsoft’s security update guidance. Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Copilot Tampering vulnerability
Microsoft Copilot Tampering vulnerability (CVE-2026-42895) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.
Azure Bot Service Elevation of Privilege vulnerability
Azure Bot Service Elevation of Privilege vulnerability (CVE-2026-32174) was added to Microsoft’s security update guidance. Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47636) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Projected File System Elevation of Privilege vulnerability
Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-42828) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c vulnerability
Linux-PAM Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. (CVE-2026-54411) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:Linux-PAM
- Product:Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.
Windows Dynamic Host Configuration Protocol (DHCP) Tampering vulnerability
Windows Dynamic Host Configuration Protocol (DHCP) Tampering vulnerability (CVE-2026-45602) was added to Microsoft’s security update guidance. Updated CWE value. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 (on-premises) Elevation of Privilege vulnerability
Microsoft Dynamics 365 (on-premises) Elevation of Privilege vulnerability (CVE-2026-40371) was added to Microsoft’s security update guidance. Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.… If you need help checking exposure, call (864) 335-9223.
Use after free in Tracing in Microsoft Edge vulnerability
Use after free in Tracing in Microsoft Edge vulnerability (CVE-2026-11701) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Bluetooth in Microsoft Edge vulnerability
Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-11700) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Bluetooth in Microsoft Edge vulnerability
Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-11699) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Microsoft Edge vulnerability (CVE-2026-11698) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Uninitialized Use in Video in Microsoft Edge vulnerability
Uninitialized Use in Video in Microsoft Edge vulnerability (CVE-2026-11697) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Inappropriate implementation in Passwords in Microsoft Edge vulnerability
Inappropriate implementation in Passwords in Microsoft Edge vulnerability (CVE-2026-11696) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in ServiceWorker in Microsoft Edge vulnerability
Use after free in ServiceWorker in Microsoft Edge vulnerability (CVE-2026-11695) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Inappropriate implementation in Plugins in Microsoft Edge vulnerability
Inappropriate implementation in Plugins in Microsoft Edge vulnerability (CVE-2026-11694) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Read Anything in Microsoft Edge vulnerability
Use after free in Read Anything in Microsoft Edge vulnerability (CVE-2026-11693) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in New Tab Page in Microsoft Edge vulnerability
Insufficient validation of untrusted input in New Tab Page in Microsoft Edge vulnerability (CVE-2026-11692) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds read and write in Media in Microsoft Edge vulnerability
Out of bounds read and write in Media in Microsoft Edge vulnerability (CVE-2026-11691) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Passwords in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Passwords in Microsoft Edge vulnerability (CVE-2026-11690) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.