Security Briefs
Page 21 of 110.
Alerts tracked
2627
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.
Showing page 21 (24 alerts) of 2627.
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50407) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50377) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
net/sched: fix packet loop on netem when duplicate is on
net net/sched: fix packet loop on netem when duplicate is on (CVE-2026-63983) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/handshake: hand off the pinned file reference to accept_doit
net net/handshake: hand off the pinned file reference to accept_doit (CVE-2026-63979) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/handshake: Drain pending requests at net namespace exit
net net/handshake: Drain pending requests at net namespace exit (CVE-2026-63978) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
hpfs: fix a crash if hpfs_map_dnode_bitmap fails vulnerability
hpfs: fix a crash if hpfs_map_dnode_bitmap fails vulnerability (CVE-2026-63954) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
WordPress Core Interpretation Conflict Vulnerability
WordPress Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-63030). WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. CISA remediation due date: 2026-07-24. If you need help checking exposure, call (864) 335-9223.
WordPress Core SQL Injection Vulnerability
WordPress Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-60137). WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. CISA remediation due date: 2026-08-04. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-58640) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-50462) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. vulnerability
A A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. (CVE-2026-38755) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. vulnerability
A A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. (CVE-2026-38754) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. vulnerability
A A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. (CVE-2026-38753) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. vulnerability
A A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. (CVE-2026-38752) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0770). Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT DD-WRT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27137). DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
FBI Warns of Scammers Impersonating the IC3
FBI Warns of Scammers Impersonating the IC3 — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.
- Vendor:FBI IC3
net: skmsg: preserve sg.copy across SG transforms
net net: skmsg: preserve sg.copy across SG transforms (CVE-2026-63830) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
net net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Active Directory Denial of Service vulnerability
Azure Active Directory Denial of Service vulnerability (CVE-2026-50653) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure Active Directory Denial of Service vulnerability
Azure Active Directory Denial of Service vulnerability (CVE-2026-50652) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50411) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50368) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50355) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.