Skip to main content

Security Briefs

Page 21 of 110.

Alerts tracked

2627

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.

Showing page 21 (24 alerts) of 2627.

Microsoft MSRC

CVE-2026-50407

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50407) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50377

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50377) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63983

net/sched: fix packet loop on netem when duplicate is on

net net/sched: fix packet loop on netem when duplicate is on (CVE-2026-63983) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-63979

net/handshake: hand off the pinned file reference to accept_doit

net net/handshake: hand off the pinned file reference to accept_doit (CVE-2026-63979) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-63978

net/handshake: Drain pending requests at net namespace exit

net net/handshake: Drain pending requests at net namespace exit (CVE-2026-63978) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-63954

hpfs: fix a crash if hpfs_map_dnode_bitmap fails vulnerability

hpfs: fix a crash if hpfs_map_dnode_bitmap fails vulnerability (CVE-2026-63954) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-63030

WordPress Core Interpretation Conflict Vulnerability

WordPress Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-63030). WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. CISA remediation due date: 2026-07-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-60137

WordPress Core SQL Injection Vulnerability

WordPress Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-60137). WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. CISA remediation due date: 2026-08-04. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58640

Windows NTFS Remote Code Execution vulnerability

Windows NTFS Remote Code Execution vulnerability (CVE-2026-58640) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50462

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-50462) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-38755

the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. vulnerability

A A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. (CVE-2026-38755) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-38754

the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. vulnerability

A A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. (CVE-2026-38754) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-38753

the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. vulnerability

A A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. (CVE-2026-38753) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-38752

the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. vulnerability

A A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. (CVE-2026-38752) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-0770

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0770). Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2021-27137

DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT DD-WRT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27137). DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Industry news

FBI Warns of Scammers Impersonating the IC3

FBI Warns of Scammers Impersonating the IC3 — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

  • Vendor:FBI IC3
Microsoft MSRC

CVE-2026-63830

net: skmsg: preserve sg.copy across SG transforms

net net: skmsg: preserve sg.copy across SG transforms (CVE-2026-63830) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-63829

net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink

net net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50653

Azure Active Directory Denial of Service vulnerability

Azure Active Directory Denial of Service vulnerability (CVE-2026-50653) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50652

Azure Active Directory Denial of Service vulnerability

Azure Active Directory Denial of Service vulnerability (CVE-2026-50652) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50411

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50411) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50368

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50368) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50355

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50355) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.