Skip to main content

Security Briefs

Page 134 of 142.

Alerts tracked

3951

Security flaws we track for Upstate SC businesses.

Known exploited

547

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

4

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.

Showing page 134 (24 alerts) of 3394.

Microsoft MSRC

CVE-2026-34871

Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0 vulnerability

An An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). (CVE-2026-34871) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-66442

Mbed TLS through 4.0.0 vulnerability

In In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. (CVE-2025-66442) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42822

Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability

Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability (CVE-2026-42822) was added to Microsoft’s security update guidance. Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32185

Microsoft Teams Spoofing vulnerability

Microsoft Teams Spoofing vulnerability (CVE-2026-32185) was added to Microsoft’s security update guidance. The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43968

CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1

CR CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 (CVE-2026-43968) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-40379

Azure Entra ID Spoofing vulnerability

Azure Entra ID Spoofing vulnerability (CVE-2026-40379) was added to Microsoft’s security update guidance. Corrected CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32170

Windows Rich Text Edit Elevation of Privilege vulnerability

Windows Rich Text Edit Elevation of Privilege vulnerability (CVE-2026-32170) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32161

Windows Native WiFi Miniport Driver Remote Code Execution vulnerability

Windows Native WiFi Miniport Driver Remote Code Execution vulnerability (CVE-2026-32161) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41615

Microsoft Authenticator Information Disclosure vulnerability

Microsoft Authenticator Information Disclosure vulnerability (CVE-2026-41615) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42833

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-42833) was added to Microsoft’s security update guidance. Updated the fixed version number. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41636

Apache Thrift: Node.js skip() recursion vulnerability

Apache Thrift: Node.js skip() recursion vulnerability (CVE-2026-41636) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41605

Apache Thrift: Swift Compact Protocol integer overflow vulnerability

Apache Thrift: Swift Compact Protocol integer overflow vulnerability (CVE-2026-41605) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41603

Apache Thrift: Java TSSLTransportFactory hostname verification vulnerability

Apache Thrift: Java TSSLTransportFactory hostname verification vulnerability (CVE-2026-41603) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41602

Apache Thrift: Go TFramedTransport uint32 overflow vulnerability

Apache Thrift: Go TFramedTransport uint32 overflow vulnerability (CVE-2026-41602) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-48431

Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. vulnerability

Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. vulnerability (CVE-2025-48431) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42896

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42896) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42893

Microsoft Outlook for iOS Tampering vulnerability

Microsoft Outlook for iOS Tampering vulnerability (CVE-2026-42893) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42832

Microsoft Office Spoofing vulnerability

Microsoft Office Spoofing vulnerability (CVE-2026-42832) was added to Microsoft’s security update guidance. Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42831

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-42831) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42830

Azure Monitor Agent Metrics Extension Elevation of Privilege vulnerability

Azure Monitor Agent Metrics Extension Elevation of Privilege vulnerability (CVE-2026-42830) was added to Microsoft’s security update guidance. Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42823

Azure Logic Apps Elevation of Privilege vulnerability

Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-42823) was added to Microsoft’s security update guidance. Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41613

Visual Studio Code Elevation of Privilege vulnerability

Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-41613) was added to Microsoft’s security update guidance. Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41612

Visual Studio Code Information Disclosure vulnerability

Visual Studio Code Information Disclosure vulnerability (CVE-2026-41612) was added to Microsoft’s security update guidance. Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41611

Visual Studio Code Remote Code Execution vulnerability

Visual Studio Code Remote Code Execution vulnerability (CVE-2026-41611) was added to Microsoft’s security update guidance. Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.