Skip to main content

Security Briefs

Page 21 of 23.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.

Showing page 21 (24 alerts) of 545.

Actively exploited (KEV)Ransomware

CVE-2021-31207

Microsoft Exchange Server Security Feature Bypass Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-31207). Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-30116

Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-30116). Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27104

Accellion FTA OS Command Injection Vulnerability

Accellion FTA is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27104). Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27103

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Accellion FTA is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27103). Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27102

Accellion FTA OS Command Injection Vulnerability

Accellion FTA is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27102). Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27101

Accellion FTA SQL Injection Vulnerability

Accellion FTA is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27101). Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27065

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27065). Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26858

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26858). Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26857

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26857). Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26855

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26855). Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26411

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26411). Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26084

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Atlassian Confluence Server and Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26084). Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-22986

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5 BIG-IP and BIG-IQ Centralized Management is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22986). F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-22893

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Ivanti Pulse Connect Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22893). Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-22205

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

GitLab Community and Enterprise Editions is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22205). GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-22005

VMware vCenter Server File Upload Vulnerability

VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22005). VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-21985

VMware vCenter Server Improper Input Validation Vulnerability

VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21985). VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-21972

VMware vCenter Server Remote Code Execution Vulnerability

VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21972). VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20023

SonicWall Email Security Path Traversal Vulnerability

SonicWall SonicWall Email Security is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20023). SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20022

SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall SonicWall Email Security is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20022). SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20021

SonicWall Email Security Improper Privilege Management Vulnerability

SonicWall SonicWall Email Security is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20021). SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20016

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20016). SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-1732

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-1732). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-1675

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-1675). Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.