Skip to main content

Security Briefs

Page 11 of 21.

Alerts tracked

2625

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.

Showing page 11 (24 alerts) of 503.

Actively exploited (KEV)Ransomware

CVE-2020-3259

Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3259). Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. CISA remediation due date: 2024-03-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21412

Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21412). Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. CISA remediation due date: 2024-03-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21762

Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21762). Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. CISA remediation due date: 2024-02-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21893

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Ivanti Connect Secure, Policy Secure, and Neurons is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21893). Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication. CISA remediation due date: 2024-02-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-22527

Atlassian Confluence Data Center and Server Template Injection Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22527). Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. CISA remediation due date: 2024-02-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-35082

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-35082). Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application. CISA remediation due date: 2024-02-08. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21887

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure and Policy Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21887). Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue. CISA remediation due date: 2024-01-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-46805

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure and Policy Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46805). Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability. CISA remediation due date: 2024-01-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-29357

Microsoft SharePoint Server Privilege Escalation Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29357). Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. CISA remediation due date: 2024-01-31. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-38203

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38203). Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CISA remediation due date: 2024-01-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-29300

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29300). Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CISA remediation due date: 2024-01-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-41266

Qlik Sense Path Traversal Vulnerability

Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-41266). Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. CISA remediation due date: 2023-12-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-41265

Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-41265). Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. CISA remediation due date: 2023-12-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-47246

SysAid Server Path Traversal Vulnerability

SysAid SysAid Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-47246). SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. CISA remediation due date: 2023-12-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-22518

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22518). Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. CISA remediation due date: 2023-11-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-46604

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46604). Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. CISA remediation due date: 2023-11-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-46747

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration Utility is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46747). F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. CISA remediation due date: 2023-11-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-4966

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4966). Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CISA remediation due date: 2023-11-08. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-40044

Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Progress WS_FTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-40044). Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. CISA remediation due date: 2023-10-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-22515

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22515). Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. CISA remediation due date: 2023-10-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-42793

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-42793). JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CISA remediation due date: 2023-10-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-3129

Laravel Ignition File Upload Vulnerability

Laravel Ignition is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-3129). Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-6884

Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-6884). Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-20269

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-20269). Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. CISA remediation due date: 2023-10-04. If you need help checking exposure, call (864) 335-9223.