Skip to main content

Security Briefs

Page 2 of 165.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 5, 2026, 6:01 AM UTC.

Showing page 2 (24 alerts) of 3939.

Microsoft MSRC

CVE-2026-55123

Microsoft PowerPoint Remote Code Execution vulnerability

Microsoft PowerPoint Remote Code Execution vulnerability (CVE-2026-55123) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55039

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55039) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40400

Windows PowerShell Remote Code Execution vulnerability

Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-88097

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-0899

Out of bounds memory access in V8 in Microsoft Edge vulnerability

Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39964). Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-39682

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39682). Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

Industry news

Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes

Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

  • Vendor:FBI IC3
Microsoft MSRC

CVE-2026-87701

Azure Cosmos DB Elevation of Privilege vulnerability

Azure Cosmos DB Elevation of Privilege vulnerability (CVE-2026-87701) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85917

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85917) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85889

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85889) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85885

Microsoft 365 Copilot Elevation of Privilege vulnerability

Microsoft 365 Copilot Elevation of Privilege vulnerability (CVE-2026-85885) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-85878

Azure Database for PostgreSQL Elevation of Privilege vulnerability

Azure Database for PostgreSQL Elevation of Privilege vulnerability (CVE-2026-85878) was added to Microsoft’s security update guidance. <p>Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-83946

Azure Portal Spoofing vulnerability

Azure Portal Spoofing vulnerability (CVE-2026-83946) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-83944

Azure Logic Apps Elevation of Privilege vulnerability

Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-83944) was added to Microsoft’s security update guidance. <p>Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78501

Microsoft 365 Copilot Business Chat Information Disclosure vulnerability

Microsoft 365 Copilot Business Chat Information Disclosure vulnerability (CVE-2026-78501) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77903

Microsoft Dataverse Elevation of Privilege vulnerability

Microsoft Dataverse Elevation of Privilege vulnerability (CVE-2026-77903) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70200

Azure Logic Apps Elevation of Privilege vulnerability

Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-70200) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70009

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-70009) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69865

Microsoft Container Registry Elevation of Privilege vulnerability

Microsoft Container Registry Elevation of Privilege vulnerability (CVE-2026-69865) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-69843

Microsoft Fabric Elevation of Privilege vulnerability

Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-69843) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69399

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-69399) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68791

Azure Machine Learning Information Disclosure vulnerability

Azure Machine Learning Information Disclosure vulnerability (CVE-2026-68791) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.