Skip to main content

Security Briefs

Page 133 of 142.

Alerts tracked

3951

Security flaws we track for Upstate SC businesses.

Known exploited

547

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

4

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.

Showing page 133 (24 alerts) of 3394.

Microsoft MSRC

CVE-2026-43502

net/rds: handle zerocopy send cleanup before the message is queued

net net/rds: handle zerocopy send cleanup before the message is queued (CVE-2026-43502) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43496

net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked

net net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (CVE-2026-43496) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43495

net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler

net net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (CVE-2026-43495) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43494

net/rds: reset op_nents when zerocopy page pin fails

net net/rds: reset op_nents when zerocopy page pin fails (CVE-2026-43494) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43465

net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ

net net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (CVE-2026-43465) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43464

net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ

net net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ (CVE-2026-43464) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34336

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-34336) was added to Microsoft’s security update guidance. The security impact for this CVE has been revised based on a re-assessment of the vulnerability. The original classification of Information Disclosure (ID) has been updated to Elevation of Privilege (EoP). If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33117

Azure SDK for Java Security Feature Bypass vulnerability

Azure SDK for Java Security Feature Bypass vulnerability (CVE-2026-33117) was added to Microsoft’s security update guidance. The executive summary has been updated to include additional details about this vulnerability. This change does not affect the available security updates. Customers should install the recommended updates to remain protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2025-40003

net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work

net net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (CVE-2025-40003) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2025-39905

net: phylink: add lock for serializing concurrent pl->phydev writes with resolver

net net: phylink: add lock for serializing concurrent pl->phydev writes with resolver (CVE-2025-39905) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-47784

memcached before 1.6.42 vulnerability

In In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. (CVE-2026-47784) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-47783

memcached before 1.6.42 vulnerability

In In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. (CVE-2026-47783) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43491

net: qrtr: ns: Limit the maximum server registration per node

net net: qrtr: ns: Limit the maximum server registration per node (CVE-2026-43491) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-40367

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-40367) was added to Microsoft’s security update guidance. Today's changes were made in error and have been reverted. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45186

libexpat before 2.8.1 vulnerability

In In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. (CVE-2026-45186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43870

Apache Thrift: Node.js web_server.js multi-vulnerability

Apache Thrift: Node.js web_server.js multi-vulnerability (CVE-2026-43870) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43869

Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability

Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability (CVE-2026-43869) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43868

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability (CVE-2026-43868) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41082

OCaml opam before 2.5.1 vulnerability

In In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. (CVE-2026-41082) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-37459

FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. vulnerability

An An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. (CVE-2026-37459) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34876

Mbed TLS 3.x before 3.6.6 vulnerability

An An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. (CVE-2026-34876) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-34874

Mbed TLS through 3.6.5 and 4.x through 4.0.0 vulnerability

An An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. (CVE-2026-34874) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34873

Mbed TLS 3.5.0 through 4.0.0 vulnerability

An An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. (CVE-2026-34873) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34872

Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0 vulnerability

An An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). (CVE-2026-34872) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.