Skip to main content

Security Briefs

Page 3 of 165.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 5, 2026, 6:01 AM UTC.

Showing page 3 (24 alerts) of 3939.

Microsoft MSRC

CVE-2026-62874

Azure Billing Elevation of Privilege vulnerability

Azure Billing Elevation of Privilege vulnerability (CVE-2026-62874) was added to Microsoft’s security update guidance. <p>Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56176

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-56176) was added to Microsoft’s security update guidance. Added Office software to the Security Updates table. Customers that are running supported version of Office are encouraged to update to the indicated version to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55946

Microsoft Copilot Information Disclosure vulnerability

Microsoft Copilot Information Disclosure vulnerability (CVE-2026-55946) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55121

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55121) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50311

Windows Server Elevation of Privilege vulnerability

Windows Server Elevation of Privilege vulnerability (CVE-2026-50311) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33835

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-33835) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-76460

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-76460). Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. CISA remediation due date: 2026-09-19. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-58704

Google Pixel Improper Authorization Vulnerability

Google Pixel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-58704). Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. CISA remediation due date: 2026-09-19. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-87559

Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability

Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability (CVE-2026-87559) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85893

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85893) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69486

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-69486) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63508

Microsoft Planetary Computer Pro Elevation of Privilege vulnerability

Microsoft Planetary Computer Pro Elevation of Privilege vulnerability (CVE-2026-63508) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55053

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55053) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50688

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-50688) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50683

Windows DHCP Client Elevation of Privilege vulnerability

Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-50683) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50351

Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability

Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability (CVE-2026-50351) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-85921

Windows Secure Kernel Mode Elevation of Privilege vulnerability

Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-85921) was added to Microsoft’s security update guidance. <p>Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco Secure Email Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-76461). Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. CISA remediation due date: 2026-09-17. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-76023

Linux Toolkit Theming vulnerability

Linux Toolkit Theming vulnerability (CVE-2026-76023) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85892

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85892) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-84869

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-84869). ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. CISA remediation due date: 2026-09-14. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84352

Use after free in WebGL in Microsoft Edge vulnerability

Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-84352) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84333

Use after free in Dawn in Microsoft Edge vulnerability

Use after free in Dawn in Microsoft Edge vulnerability (CVE-2026-84333) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84330

UI misrepresentation in FullScreen in Microsoft Edge vulnerability

UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84330) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.