Skip to main content

Security Briefs

Page 17 of 89.

Alerts tracked

2627

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.

Showing page 17 (24 alerts) of 2116.

Microsoft MSRC

CVE-2026-57104

Azure Storage Explorer Elevation of Privilege vulnerability

Azure Storage Explorer Elevation of Privilege vulnerability (CVE-2026-57104) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56179

Windows Network Address Translation (NAT) Spoofing vulnerability

Windows Network Address Translation (NAT) Spoofing vulnerability (CVE-2026-56179) was added to Microsoft’s security update guidance. Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56174

Windows Narrator Braille Elevation of Privilege vulnerability

Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-56174) was added to Microsoft’s security update guidance. Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54984

Windows Imaging Component Remote Code Execution vulnerability

Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-54984) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54981

Visual Studio Code Python Extension Security Feature Bypass vulnerability

Visual Studio Code Python Extension Security Feature Bypass vulnerability (CVE-2026-54981) was added to Microsoft’s security update guidance. Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54123

Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability

Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability (CVE-2026-54123) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50472

Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability

Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability (CVE-2026-50472) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49179

Windows Active Directory Domain Services Remote Code Execution vulnerability

Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-49179) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47299

Azure Monitor Agent Elevation of Privilege vulnerability

Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-47299) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47285

Visual Studio Code Information Disclosure vulnerability

Visual Studio Code Information Disclosure vulnerability (CVE-2026-47285) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43871

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability (CVE-2026-43871) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40375

Microsoft Dynamics Business Central Information Disclosure vulnerability

Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2026-40375) was added to Microsoft’s security update guidance. Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50357

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50357) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40417

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2026-40417) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2025-29821

Microsoft Dynamics Business Central Information Disclosure vulnerability

Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2025-29821) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2024-38225

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-38225) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability (CVE-2024-21380) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2021-40440

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-40440) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2021-36946

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-36946) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2021-34474

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability (CVE-2021-34474) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2025-49506

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability (CVE-2025-49506) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70332

Microsoft Office SharePoint Spoofing vulnerability

Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-70332) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68823

Azure Confidential Ledger Remote Code Execution vulnerability

Azure Confidential Ledger Remote Code Execution vulnerability (CVE-2026-68823) was added to Microsoft’s security update guidance. Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65668

Microsoft Purview eDiscovery Elevation of Privilege vulnerability

Microsoft Purview eDiscovery Elevation of Privilege vulnerability (CVE-2026-65668) was added to Microsoft’s security update guidance. Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.