Security Briefs
Page 140 of 142.
Alerts tracked
3951
Security flaws we track for Upstate SC businesses.
Known exploited
547
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
4
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.
Showing page 140 (24 alerts) of 3394.
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-33111) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33109) was added to Microsoft’s security update guidance. Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_authn_socache crash vulnerability
Apache HTTP Server: mod_authn_socache crash vulnerability (CVE-2026-33007) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_auth_digest timing attack vulnerability
Apache HTTP Server: mod_auth_digest timing attack vulnerability (CVE-2026-33006) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Machine Learning Notebook Spoofing vulnerability
Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-32207) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_dav_lock indirect lock crash vulnerability
Apache HTTP Server: mod_dav_lock indirect lock crash vulnerability (CVE-2026-29169) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_md unrestricted OCSP response vulnerability
Apache HTTP Server: mod_md unrestricted OCSP response vulnerability (CVE-2026-29168) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr vulnerability
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr vulnerability (CVE-2026-24072) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: http2: double free and possible RCE on early reset vulnerability
Apache HTTP Server: http2: double free and possible RCE on early reset vulnerability (CVE-2026-23918) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels
net net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels (CVE-2025-71285) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
inet: frags: flush pending skbs in fqdir_pre_exit()
inet inet: frags: flush pending skbs in fqdir_pre_exit() (CVE-2025-68768) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Util-linux: util-linux: access control bypass due to improper hostname canonicalization vulnerability
Util-linux: util-linux: access control bypass due to improper hostname canonicalization vulnerability (CVE-2026-3184) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
-EBUSY error path of tls_do_encryption vulnerability
net net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
util-linux mount(8) - Loop Device Setup vulnerability
util-linux mount(8) - Loop Device Setup vulnerability (CVE-2026-27456) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Thrift: Swift Range crash in skip()
Apache Apache Thrift: Swift Range crash in skip() (CVE-2026-41604) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
JsonTemplateLayout vulnerability
Apache Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout (CVE-2026-34481) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Apache Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34480) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters vulnerability
Apache Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34479) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
TLS configuration vulnerability
Apache Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass (CVE-2026-34477) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability
Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability (CVE-2026-3298) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
bond_debug_rlb_hash_show vulnerability
net net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: openvswitch: Avoid releasing netdev before teardown completes vulnerability
net net: openvswitch: Avoid releasing netdev before teardown completes (CVE-2026-31508) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: skb: fix cross-cache free of KFENCE-allocated skb head vulnerability
net net: skb: fix cross-cache free of KFENCE-allocated skb head (CVE-2026-31429) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: macb: Use dev_consume_skb_any() to free TX SKBs vulnerability
net net: macb: Use dev_consume_skb_any() to free TX SKBs (CVE-2026-31563) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.