Skip to main content

Security Briefs

Page 140 of 142.

Alerts tracked

3951

Security flaws we track for Upstate SC businesses.

Known exploited

547

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

4

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.

Showing page 140 (24 alerts) of 3394.

Microsoft MSRC

CVE-2026-33111

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-33111) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33109

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33109) was added to Microsoft’s security update guidance. Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33007

Apache HTTP Server: mod_authn_socache crash vulnerability

Apache HTTP Server: mod_authn_socache crash vulnerability (CVE-2026-33007) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33006

Apache HTTP Server: mod_auth_digest timing attack vulnerability

Apache HTTP Server: mod_auth_digest timing attack vulnerability (CVE-2026-33006) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32207

Azure Machine Learning Notebook Spoofing vulnerability

Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-32207) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-29169

Apache HTTP Server: mod_dav_lock indirect lock crash vulnerability

Apache HTTP Server: mod_dav_lock indirect lock crash vulnerability (CVE-2026-29169) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-29168

Apache HTTP Server: mod_md unrestricted OCSP response vulnerability

Apache HTTP Server: mod_md unrestricted OCSP response vulnerability (CVE-2026-29168) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-24072

Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr vulnerability

Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr vulnerability (CVE-2026-24072) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23918

Apache HTTP Server: http2: double free and possible RCE on early reset vulnerability

Apache HTTP Server: http2: double free and possible RCE on early reset vulnerability (CVE-2026-23918) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-71285

net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels

net net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels (CVE-2025-71285) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-68768

inet: frags: flush pending skbs in fqdir_pre_exit()

inet inet: frags: flush pending skbs in fqdir_pre_exit() (CVE-2025-68768) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-3184

Util-linux: util-linux: access control bypass due to improper hostname canonicalization vulnerability

Util-linux: util-linux: access control bypass due to improper hostname canonicalization vulnerability (CVE-2026-3184) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31533

-EBUSY error path of tls_do_encryption vulnerability

net net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-27456

util-linux mount(8) - Loop Device Setup vulnerability

util-linux mount(8) - Loop Device Setup vulnerability (CVE-2026-27456) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41604

Apache Thrift: Swift Range crash in skip()

Apache Apache Thrift: Swift Range crash in skip() (CVE-2026-41604) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34481

JsonTemplateLayout vulnerability

Apache Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout (CVE-2026-34481) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34480

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

Apache Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34480) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34479

Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters vulnerability

Apache Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34479) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34477

TLS configuration vulnerability

Apache Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass (CVE-2026-34477) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-3298

Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability

Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability (CVE-2026-3298) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31546

bond_debug_rlb_hash_show vulnerability

net net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31508

net: openvswitch: Avoid releasing netdev before teardown completes vulnerability

net net: openvswitch: Avoid releasing netdev before teardown completes (CVE-2026-31508) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31429

net: skb: fix cross-cache free of KFENCE-allocated skb head vulnerability

net net: skb: fix cross-cache free of KFENCE-allocated skb head (CVE-2026-31429) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31563

net: macb: Use dev_consume_skb_any() to free TX SKBs vulnerability

net net: macb: Use dev_consume_skb_any() to free TX SKBs (CVE-2026-31563) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.