Skip to main content

Security Briefs

Page 139 of 142.

Alerts tracked

3951

Security flaws we track for Upstate SC businesses.

Known exploited

547

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

4

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.

Showing page 139 (24 alerts) of 3394.

MediumMicrosoft MSRC

CVE-2024-25740

the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT vulnerability

A A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released. (CVE-2024-25740) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2024-23848

the Linux kernel through 6.7.1 vulnerability

In In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. (CVE-2024-23848) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2022-4543

the Linux Kernel Page Table Isolation (KPTI) vulnerability

A A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. (CVE-2022-4543) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43274

mchp_ipc_get_cluster_aggr_irq() vulnerability

mchp_ipc_get_cluster_aggr_irq() vulnerability (CVE-2026-43274) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-8021

UI vulnerability

UI vulnerability (CVE-2026-8021) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-7992

UI vulnerability

UI vulnerability (CVE-2026-7992) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-7991

UI vulnerability

UI vulnerability (CVE-2026-7991) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43219

net: cpsw_new: Fix potential unregister of netdev that has not been registered yet

net net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (CVE-2026-43219) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43216

skb_may_tx_timestamp() vulnerability

net net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43199

net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query

net net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (CVE-2026-43199) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43088

net: af_key: zero aligned sockaddr tail in PF_KEY exports

net net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43083

net: ioam6: fix OOB and missing lock

net net: ioam6: fix OOB and missing lock (CVE-2026-43083) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42826

Azure DevOps Information Disclosure vulnerability

Azure DevOps Information Disclosure vulnerability (CVE-2026-42826) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41105

Azure Monitor Action Group Notification System Elevation of Privilege vulnerability

Azure Monitor Action Group Notification System Elevation of Privilege vulnerability (CVE-2026-41105) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35435

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-35435) was added to Microsoft’s security update guidance. Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35428

Azure Cloud Shell Spoofing vulnerability

Azure Cloud Shell Spoofing vulnerability (CVE-2026-35428) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-34327

Microsoft Partner Center Spoofing vulnerability

Microsoft Partner Center Spoofing vulnerability (CVE-2026-34327) was added to Microsoft’s security update guidance. Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34059

Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()

Apache Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() (CVE-2026-34059) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2026-34032

Apache Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) vulnerability

Apache Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) vulnerability (CVE-2026-34032) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33857

Apache HTTP Server: Off-by-one OOB reads in AJP getter functions

Apache Apache HTTP Server: Off-by-one OOB reads in AJP getter functions (CVE-2026-33857) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

CriticalMicrosoft MSRC

CVE-2026-33844

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33844) was added to Microsoft’s security update guidance. Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33823

Microsoft Team Events Portal Information Disclosure vulnerability

Microsoft Team Events Portal Information Disclosure vulnerability (CVE-2026-33823) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33821

Microsoft Dynamics 365 Customer Insights Elevation of Privilege vulnerability

Microsoft Dynamics 365 Customer Insights Elevation of Privilege vulnerability (CVE-2026-33821) was added to Microsoft’s security update guidance. Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33523

Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line vulnerability

Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line vulnerability (CVE-2026-33523) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.