Skip to main content

Security Briefs

Page 126 of 165.

Alerts tracked

3951

Security flaws we track for Upstate SC businesses.

Known exploited

547

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

4

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.

Showing page 126 (24 alerts) of 3951.

Microsoft MSRC

CVE-2026-12008

Use after free DigitalCredentials in Microsoft Edge vulnerability

Use after free DigitalCredentials in Microsoft Edge vulnerability (CVE-2026-12008) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-12007

Use after free Core in Microsoft Edge vulnerability

Use after free Core in Microsoft Edge vulnerability (CVE-2026-12007) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49975

Apache HTTP Server: mod_http2 denial of service vulnerability

Apache HTTP Server: mod_http2 denial of service vulnerability (CVE-2026-49975) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-35273). Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. CISA remediation due date: 2026-06-15. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48913

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted vulnerability

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted vulnerability (CVE-2026-48913) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-44631

Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow

Apache Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow (CVE-2026-44631) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44186

Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp

Apache Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp (CVE-2026-44186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44185

Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`

Apache Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (CVE-2026-44185) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44119

Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules

Apache Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules (CVE-2026-44119) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43951

Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash

Apache Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash (CVE-2026-43951) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42536

Apache HTTP Server: mod_xml2enc heap overflow vulnerability

Apache HTTP Server: mod_xml2enc heap overflow vulnerability (CVE-2026-42536) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42535

Apache HTTP Server: mod_dav_fs protected directory access vulnerability

Apache HTTP Server: mod_dav_fs protected directory access vulnerability (CVE-2026-42535) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34356

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow vulnerability

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow vulnerability (CVE-2026-34356) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34355

Apache HTTP Server: mod_proxy_html buffer overflow vulnerability

Apache HTTP Server: mod_proxy_html buffer overflow vulnerability (CVE-2026-34355) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-29170

Apache HTTP Server: mod_proxy_ftp XSS vulnerability

Apache HTTP Server: mod_proxy_ftp XSS vulnerability (CVE-2026-29170) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-29167

Apache HTTP Server: mod_ldap per-dir use-after-free vulnerability

Apache HTTP Server: mod_ldap per-dir use-after-free vulnerability (CVE-2026-29167) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-10520). Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. CISA remediation due date: 2026-06-14. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-48569

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-48569) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47298

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47298) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47294

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47294) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-46319

net/sched: act_ct: Only release RCU read lock after ct_ft

net net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-46287

net: txgbe: fix RTNL assertion warning when remove module

net net: txgbe: fix RTNL assertion warning when remove module (CVE-2026-46287) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-45482

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability (CVE-2026-45482) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number and Title as the Chat extention is now merged into Visual Studio Code If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40376

Visual Studio Code Elevation of Privilege vulnerability

Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-40376) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.