Skip to main content

Security Briefs

Page 19 of 110.

Alerts tracked

2627

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.

Showing page 19 (24 alerts) of 2627.

Microsoft MSRC

CVE-2026-50481

Azure Active Directory Elevation of Privilege vulnerability

Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Industry news

Ongoing Threats of Swatting and Indicators for Community Members

Ongoing Threats of Swatting and Indicators for Community Members — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

  • Vendor:FBI IC3
Actively exploited (KEV)

CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. CISA remediation due date: 2026-08-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CISA remediation due date: 2026-08-07. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50341

Windows NTFS Information Disclosure vulnerability

Windows NTFS Information Disclosure vulnerability (CVE-2026-50341) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18577). N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. CISA remediation due date: 2026-08-06. If you need help checking exposure, call (864) 335-9223.

Industry news

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

  • Vendor:FBI IC3
Microsoft MSRC

CVE-2026-66803

Azure Cosmos DB Remote Code Execution vulnerability

Azure Cosmos DB Remote Code Execution vulnerability (CVE-2026-66803) was added to Microsoft’s security update guidance. Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56197

Windows Admin Center (WAC) Remote Code Execution vulnerability

Windows Admin Center (WAC) Remote Code Execution vulnerability (CVE-2026-56197) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55129

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55129) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54128

Windows DHCP Client Remote Code Execution vulnerability

Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-54128) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-24304

Azure Resource Manager Elevation of Privilege vulnerability

Azure Resource Manager Elevation of Privilege vulnerability (CVE-2026-24304) was added to Microsoft’s security update guidance. Informational Change. CVE ID stays the same. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20316

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco Secure Firewall Management Center (FMC) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20316). Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. CISA remediation due date: 2026-08-01. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59117

Windows Terminal Remote Code Execution vulnerability

Windows Terminal Remote Code Execution vulnerability (CVE-2026-59117) was added to Microsoft’s security update guidance. Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50422

Windows NTFS Elevation of Privilege vulnerability

Windows NTFS Elevation of Privilege vulnerability (CVE-2026-50422) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13037

Use after free in WebView in Microsoft Edge vulnerability

Use after free in WebView in Microsoft Edge vulnerability (CVE-2026-13037) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13032

Use after free in WebGL in Microsoft Edge vulnerability

Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-13032) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13030

Uninitialized Use in GPU in Microsoft Edge vulnerability

Uninitialized Use in GPU in Microsoft Edge vulnerability (CVE-2026-13030) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13028

Use after free in WebGL in Microsoft Edge vulnerability

Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-13028) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50697

Windows Common Log File System Driver Elevation of Privilege vulnerability

Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-50697) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50343

Microsoft Install Service Elevation of Privilege vulnerability

Microsoft Install Service Elevation of Privilege vulnerability (CVE-2026-50343) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50333

Windows Spaceport.sys Elevation of Privilege vulnerability

Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-50333) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-68686

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-68686). Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. CISA remediation due date: 2026-08-10. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-16807

Out of bounds write in Codecs in Microsoft Edge vulnerability

Out of bounds write in Codecs in Microsoft Edge vulnerability (CVE-2026-16807) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.