Security Briefs
Page 20 of 23.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.
Showing page 20 (24 alerts) of 545.
Oracle WebLogic Server, Injection vulnerability
Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-2725). Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1579). Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1458). A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy Out-of-bounds Write vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13383). A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy Improper Authorization vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13382). An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Installer Spoofing Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-43890). Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. CISA remediation due date: 2021-12-29. If you need help checking exposure, call (864) 335-9223.
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44228). Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. CISA remediation due date: 2021-12-24. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Red Hat JBoss Application Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12149). The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. CISA remediation due date: 2022-06-10. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server-Side Request Forgery (SSRF) vulnerability
Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42321). An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Win32k Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40449). Unspecified vulnerability allows for an authenticated user to escalate privileges. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.
BQE BillQuick Web Suite SQL Injection Vulnerability
BQE BillQuick Web Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42258). BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server Path Traversal Vulnerability
Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42013). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Apache HTTP Server Path Traversal Vulnerability
Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41773). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Zoho ManageEngine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40539). Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft MSHTML Remote Code Execution Vulnerability
Microsoft MSHTML is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40444). Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Microsoft Open Management Infrastructure (OMI) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-38647). Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-36955). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-36942). Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
ForgeRock Access Management (AM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-35464). ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
SolarWinds Serv-U Remote Code Execution Vulnerability
SolarWinds Serv-U is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-35211). SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-34527). Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-34523). Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-34473). Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.