Skip to main content

Security Briefs

Page 23 of 111.

Alerts tracked

2649

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 21, 2026, 6:00 AM UTC.

Showing page 23 (24 alerts) of 2649.

Microsoft MSRC

CVE-2026-50324

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50324) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50304

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50304) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2024-35248

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-35248) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15905

Use after free in Aura in Microsoft Edge vulnerability

Use after free in Aura in Microsoft Edge vulnerability (CVE-2026-15905) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15904

Use after free in Ozone in Microsoft Edge vulnerability

Use after free in Ozone in Microsoft Edge vulnerability (CVE-2026-15904) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15903

Out of bounds read and write in V8 in Microsoft Edge vulnerability

Out of bounds read and write in V8 in Microsoft Edge vulnerability (CVE-2026-15903) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15902

Use after free in Cast in Microsoft Edge vulnerability

Use after free in Cast in Microsoft Edge vulnerability (CVE-2026-15902) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15901

Use after free in Network in Microsoft Edge vulnerability

Use after free in Network in Microsoft Edge vulnerability (CVE-2026-15901) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15900

Use after free in GPU in Microsoft Edge vulnerability

Use after free in GPU in Microsoft Edge vulnerability (CVE-2026-15900) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-15899

Use after free in CameraCapture in Microsoft Edge vulnerability

Use after free in CameraCapture in Microsoft Edge vulnerability (CVE-2026-15899) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58598

Windows Backup Service Elevation of Privilege vulnerability

Windows Backup Service Elevation of Privilege vulnerability (CVE-2026-58598) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56171

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-56171) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-39808

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-39808). Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. CISA remediation due date: 2026-07-19. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-25089). Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. CISA remediation due date: 2026-07-19. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58644

Microsoft SharePoint Remote Code Execution vulnerability

Microsoft SharePoint Remote Code Execution vulnerability (CVE-2026-58644) was added to Microsoft’s security update guidance. Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56182

Windows NTFS Elevation of Privilege vulnerability

Windows NTFS Elevation of Privilege vulnerability (CVE-2026-56182) was added to Microsoft’s security update guidance. Updated acknowledgment. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-46817

Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-46817). Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CISA remediation due date: 2026-07-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-39822

os vulnerability

os vulnerability (CVE-2026-39822) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2023-4346

KNX Protocol Connection Authorization Option 1 vulnerability

KNX Association KNX Protocol Connection Authorization Option 1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4346). KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. CISA remediation due date: 2026-07-29. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58638

Windows Boot Loader Security Feature Bypass vulnerability

Windows Boot Loader Security Feature Bypass vulnerability (CVE-2026-58638) was added to Microsoft’s security update guidance. Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58637

Windows Client-Side Caching Elevation of Privilege vulnerability

Windows Client-Side Caching Elevation of Privilege vulnerability (CVE-2026-58637) was added to Microsoft’s security update guidance. Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58636

Microsoft PC Manager Elevation of Privilege vulnerability

Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-58636) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58635

Windows Narrator Braille Elevation of Privilege vulnerability

Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-58635) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58632

Windows Win32 Kernel Subsystem Elevation of Privilege vulnerability

Windows Win32 Kernel Subsystem Elevation of Privilege vulnerability (CVE-2026-58632) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.