Security Briefs
Page 23 of 111.
Alerts tracked
2649
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 21, 2026, 6:00 AM UTC.
Showing page 23 (24 alerts) of 2649.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50324) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50304) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-35248) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Use after free in Aura in Microsoft Edge vulnerability
Use after free in Aura in Microsoft Edge vulnerability (CVE-2026-15905) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Ozone in Microsoft Edge vulnerability
Use after free in Ozone in Microsoft Edge vulnerability (CVE-2026-15904) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds read and write in V8 in Microsoft Edge vulnerability
Out of bounds read and write in V8 in Microsoft Edge vulnerability (CVE-2026-15903) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Cast in Microsoft Edge vulnerability
Use after free in Cast in Microsoft Edge vulnerability (CVE-2026-15902) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Network in Microsoft Edge vulnerability
Use after free in Network in Microsoft Edge vulnerability (CVE-2026-15901) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in GPU in Microsoft Edge vulnerability
Use after free in GPU in Microsoft Edge vulnerability (CVE-2026-15900) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in CameraCapture in Microsoft Edge vulnerability
Use after free in CameraCapture in Microsoft Edge vulnerability (CVE-2026-15899) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Windows Backup Service Elevation of Privilege vulnerability
Windows Backup Service Elevation of Privilege vulnerability (CVE-2026-58598) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-56171) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-39808). Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. CISA remediation due date: 2026-07-19. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-25089). Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. CISA remediation due date: 2026-07-19. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Remote Code Execution vulnerability
Microsoft SharePoint Remote Code Execution vulnerability (CVE-2026-58644) was added to Microsoft’s security update guidance. Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-56182) was added to Microsoft’s security update guidance. Updated acknowledgment. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-46817). Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CISA remediation due date: 2026-07-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
os vulnerability
os vulnerability (CVE-2026-39822) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
KNX Protocol Connection Authorization Option 1 vulnerability
KNX Association KNX Protocol Connection Authorization Option 1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4346). KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. CISA remediation due date: 2026-07-29. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Boot Loader Security Feature Bypass vulnerability
Windows Boot Loader Security Feature Bypass vulnerability (CVE-2026-58638) was added to Microsoft’s security update guidance. Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Client-Side Caching Elevation of Privilege vulnerability
Windows Client-Side Caching Elevation of Privilege vulnerability (CVE-2026-58637) was added to Microsoft’s security update guidance. Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft PC Manager Elevation of Privilege vulnerability
Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-58636) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Narrator Braille Elevation of Privilege vulnerability
Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-58635) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Win32 Kernel Subsystem Elevation of Privilege vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege vulnerability (CVE-2026-58632) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.