Skip to main content

Security Briefs

Page 138 of 142.

Alerts tracked

3951

Security flaws we track for Upstate SC businesses.

Known exploited

547

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

4

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.

Showing page 138 (24 alerts) of 3394.

Microsoft MSRC

CVE-2026-33837

Windows TCP/IP Local Elevation of Privilege vulnerability

Windows TCP/IP Local Elevation of Privilege vulnerability (CVE-2026-33837) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33834

Windows Event Logging Service Elevation of Privilege vulnerability

Windows Event Logging Service Elevation of Privilege vulnerability (CVE-2026-33834) was added to Microsoft’s security update guidance. Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33833

Azure Machine Learning Notebook Spoofing vulnerability

Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-33833) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33112

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33112) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33110

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33110) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32209

Windows Filtering Platform (WFP) Security Feature Bypass vulnerability

Windows Filtering Platform (WFP) Security Feature Bypass vulnerability (CVE-2026-32209) was added to Microsoft’s security update guidance. Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32204

Azure Monitor Agent Elevation of Privilege vulnerability

Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-32204) was added to Microsoft’s security update guidance. External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43036

net: use skb_header_pointer() for TCPv4 GSO frag_off check vulnerability

net net: use skb_header_pointer() for TCPv4 GSO frag_off check (CVE-2026-43036) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-31419

net: bonding: fix use-after-free in bond_xmit_broadcast()

net net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23276

net: add xmit recursion limit to tunnel xmit functions

net net: add xmit recursion limit to tunnel xmit functions (CVE-2026-23276) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-20841

Windows Notepad App Remote Code Execution vulnerability

Windows Notepad App Remote Code Execution vulnerability (CVE-2026-20841) was added to Microsoft’s security update guidance. Added FAQ information. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-68338

net: dsa: microchip: Don't free uninitialized ksz_irq

net net: dsa: microchip: Don't free uninitialized ksz_irq (CVE-2025-68338) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-40170

net: use dst_dev_rcu() in sk_setup_caps()

net net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2025-39677

net/sched: Fix backlog accounting in qdisc_dequeue_internal

net net/sched: Fix backlog accounting in qdisc_dequeue_internal (CVE-2025-39677) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2025-38717

net: kcm: Fix race condition in kcm_unattach()

net net: kcm: Fix race condition in kcm_unattach() (CVE-2025-38717) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2025-38272

net: dsa: b53: do not enable EEE on bcm63xx

net net: dsa: b53: do not enable EEE on bcm63xx (CVE-2025-38272) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2025-21801

net: ravb: Fix missing rtnl lock in suspend/resume path

net net: ravb: Fix missing rtnl lock in suspend/resume path (CVE-2025-21801) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2025-21768

net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels

net net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels (CVE-2025-21768) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2025-21649

net: hns3: fix kernel crash when 1588 is sent on HIP08 devices

net net: hns3: fix kernel crash when 1588 is sent on HIP08 devices (CVE-2025-21649) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2024-56647

net: Fix icmp host relookup triggering ip_rt_bug vulnerability

net net: Fix icmp host relookup triggering ip_rt_bug (CVE-2024-56647) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2024-49945

net/ncsi: Disable the ncsi work before freeing the associated structure

net net/ncsi: Disable the ncsi work before freeing the associated structure (CVE-2024-49945) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2024-40999

net: ena: Add validation for completion descriptors consistency

net net: ena: Add validation for completion descriptors consistency (CVE-2024-40999) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2024-38608

net/mlx5e: Fix netif state handling

net net/mlx5e: Fix netif state handling (CVE-2024-38608) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2024-38595

net/mlx5: Fix peer devlink set for SF representor devlink port

net net/mlx5: Fix peer devlink set for SF representor devlink port (CVE-2024-38595) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.