Security Briefs
Page 141 of 142.
Alerts tracked
3951
Security flaws we track for Upstate SC businesses.
Known exploited
547
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
4
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 9, 2026, 6:01 AM UTC.
Showing page 141 (24 alerts) of 3394.
Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Windows Graphics Component Elevation of Privilege (CVE-2026-21246) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Microsoft Dynamics 365 (On-Premises) Information Disclosure (CVE-2026-33103) was added to Microsoft’s security update guidance. Added acknowledgements. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Power Apps Desktop Client Spoofing Vulnerability
Microsoft Microsoft Power Apps Desktop Client Spoofing (CVE-2026-26149) was added to Microsoft’s security update guidance. CVE-2026-26149 Microsoft Power Apps Desktop Client Spoofing Vulnerability PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: sched: act_csum: validate nested VLAN headers vulnerability
net net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: ipv6: flowlabel: defer exclusive option free until RCU teardown vulnerability
net net: ipv6: flowlabel: defer exclusive option free until RCU teardown (CVE-2026-31680) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
packet corruption vulnerability
net net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: rfkill: prevent unlimited numbers of rfkill events from being created vulnerability
net net: rfkill: prevent unlimited numbers of rfkill events from being created (CVE-2026-31670) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
tse_start_xmit() vulnerability
net net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
chain mode vulnerability
net net: stmmac: fix integer underflow in chain mode (CVE-2026-31649) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
lan966x_fdma_rx_alloc_page_pool() vulnerability
net net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (CVE-2026-31646) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: lan966x: fix page pool leak in error paths
net net: lan966x: fix page pool leak in error paths (CVE-2026-31645) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
rx_complete() vulnerability
net net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (CVE-2026-31623) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled vulnerability
net net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-23381) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
the offload path vulnerability
net net/sched: ets: fix divide by zero in the offload path (CVE-2026-23379) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/sched: act_ife: Fix metalist update behavior vulnerability
net net/sched: act_ife: Fix metalist update behavior (CVE-2026-23378) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: phy: register phy led_triggers during probe to avoid AB-BA deadlock vulnerability
net net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (CVE-2026-23368) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: usb: kalmia: validate USB endpoints vulnerability
net net: usb: kalmia: validate USB endpoints (CVE-2026-23365) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check vulnerability
net net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check (CVE-2026-23447) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: usb: aqc111: Do not perform PM inside suspend callback vulnerability
net net: usb: aqc111: Do not perform PM inside suspend callback (CVE-2026-23446) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
buffer switching vulnerability
net net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs vulnerability
net net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (CVE-2026-23340) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Microsoft Microsoft Entra ID Entitlement Management Spoofing (CVE-2026-35431) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Bing Remote Code Execution Vulnerability
Microsoft Microsoft Bing Remote Code Execution (CVE-2026-33819) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft 365 Copilot Elevation of Privilege Vulnerability
Microsoft Microsoft 365 Copilot Elevation of Privilege (CVE-2026-33102) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.