Security Briefs
Page 138 of 142.
Alerts tracked
3951
Security flaws we track for Upstate SC businesses.
Known exploited
547
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
4
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.
Showing page 138 (24 alerts) of 3394.
Windows TCP/IP Local Elevation of Privilege vulnerability
Windows TCP/IP Local Elevation of Privilege vulnerability (CVE-2026-33837) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Event Logging Service Elevation of Privilege vulnerability
Windows Event Logging Service Elevation of Privilege vulnerability (CVE-2026-33834) was added to Microsoft’s security update guidance. Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Machine Learning Notebook Spoofing vulnerability
Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-33833) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33112) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33110) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Filtering Platform (WFP) Security Feature Bypass vulnerability
Windows Filtering Platform (WFP) Security Feature Bypass vulnerability (CVE-2026-32209) was added to Microsoft’s security update guidance. Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Monitor Agent Elevation of Privilege vulnerability
Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-32204) was added to Microsoft’s security update guidance. External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: use skb_header_pointer() for TCPv4 GSO frag_off check vulnerability
net net: use skb_header_pointer() for TCPv4 GSO frag_off check (CVE-2026-43036) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: bonding: fix use-after-free in bond_xmit_broadcast()
net net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: add xmit recursion limit to tunnel xmit functions
net net: add xmit recursion limit to tunnel xmit functions (CVE-2026-23276) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Notepad App Remote Code Execution vulnerability
Windows Notepad App Remote Code Execution vulnerability (CVE-2026-20841) was added to Microsoft’s security update guidance. Added FAQ information. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: dsa: microchip: Don't free uninitialized ksz_irq
net net: dsa: microchip: Don't free uninitialized ksz_irq (CVE-2025-68338) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: use dst_dev_rcu() in sk_setup_caps()
net net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/sched: Fix backlog accounting in qdisc_dequeue_internal
net net/sched: Fix backlog accounting in qdisc_dequeue_internal (CVE-2025-39677) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: kcm: Fix race condition in kcm_unattach()
net net: kcm: Fix race condition in kcm_unattach() (CVE-2025-38717) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: dsa: b53: do not enable EEE on bcm63xx
net net: dsa: b53: do not enable EEE on bcm63xx (CVE-2025-38272) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: ravb: Fix missing rtnl lock in suspend/resume path
net net: ravb: Fix missing rtnl lock in suspend/resume path (CVE-2025-21801) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
net net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels (CVE-2025-21768) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: hns3: fix kernel crash when 1588 is sent on HIP08 devices
net net: hns3: fix kernel crash when 1588 is sent on HIP08 devices (CVE-2025-21649) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: Fix icmp host relookup triggering ip_rt_bug vulnerability
net net: Fix icmp host relookup triggering ip_rt_bug (CVE-2024-56647) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/ncsi: Disable the ncsi work before freeing the associated structure
net net/ncsi: Disable the ncsi work before freeing the associated structure (CVE-2024-49945) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: ena: Add validation for completion descriptors consistency
net net: ena: Add validation for completion descriptors consistency (CVE-2024-40999) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/mlx5e: Fix netif state handling
net net/mlx5e: Fix netif state handling (CVE-2024-38608) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/mlx5: Fix peer devlink set for SF representor devlink port
net net/mlx5: Fix peer devlink set for SF representor devlink port (CVE-2024-38595) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.