Security Briefs
Page 18 of 21.
Alerts tracked
2627
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.
Showing page 18 (24 alerts) of 503.
Microsoft SMBv3 Remote Code Execution Vulnerability
Microsoft SMBv3 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0796). A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-10271). Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0145). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0144). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21882). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-02-18. If you need help checking exposure, call (864) 335-9223.
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
SonicWall SMA 100 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20038). SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. CISA remediation due date: 2022-02-11. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0787). Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. CISA remediation due date: 2022-07-28. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8453). Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. CISA remediation due date: 2022-07-21. If you need help checking exposure, call (864) 335-9223.
VMware Server Side Request Forgery in vRealize Operations Manager API vulnerability
VMware vRealize Operations Manager API is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21975). Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. CISA remediation due date: 2022-02-01. If you need help checking exposure, call (864) 335-9223.
Oracle WebLogic Server, Injection vulnerability
Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-2725). Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1579). Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1458). A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy Out-of-bounds Write vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13383). A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy Improper Authorization vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13382). An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Installer Spoofing Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-43890). Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. CISA remediation due date: 2021-12-29. If you need help checking exposure, call (864) 335-9223.
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44228). Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. CISA remediation due date: 2021-12-24. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Red Hat JBoss Application Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12149). The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. CISA remediation due date: 2022-06-10. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server-Side Request Forgery (SSRF) vulnerability
Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42321). An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Win32k Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40449). Unspecified vulnerability allows for an authenticated user to escalate privileges. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.
BQE BillQuick Web Suite SQL Injection Vulnerability
BQE BillQuick Web Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42258). BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server Path Traversal Vulnerability
Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42013). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server Path Traversal Vulnerability
Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41773). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Zoho ManageEngine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40539). Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.