Security Briefs
Page 3 of 165.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 5, 2026, 6:01 AM UTC.
Showing page 3 (24 alerts) of 3939.
Azure Billing Elevation of Privilege vulnerability
Azure Billing Elevation of Privilege vulnerability (CVE-2026-62874) was added to Microsoft’s security update guidance. <p>Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-56176) was added to Microsoft’s security update guidance. Added Office software to the Security Updates table. Customers that are running supported version of Office are encouraged to update to the indicated version to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.
Microsoft Copilot Information Disclosure vulnerability
Microsoft Copilot Information Disclosure vulnerability (CVE-2026-55946) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55121) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Server Elevation of Privilege vulnerability
Windows Server Elevation of Privilege vulnerability (CVE-2026-50311) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-33835) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-76460). Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. CISA remediation due date: 2026-09-19. If you need help checking exposure, call (864) 335-9223.
Google Pixel Improper Authorization Vulnerability
Google Pixel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-58704). Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. CISA remediation due date: 2026-09-19. If you need help checking exposure, call (864) 335-9223.
Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability
Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability (CVE-2026-87559) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85893) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-69486) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Planetary Computer Pro Elevation of Privilege vulnerability
Microsoft Planetary Computer Pro Elevation of Privilege vulnerability (CVE-2026-63508) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55053) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-50688) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Elevation of Privilege vulnerability
Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-50683) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability
Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability (CVE-2026-50351) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Secure Kernel Mode Elevation of Privilege vulnerability
Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-85921) was added to Microsoft’s security update guidance. <p>Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco Secure Email Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-76461). Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. CISA remediation due date: 2026-09-17. If you need help checking exposure, call (864) 335-9223.
Linux Toolkit Theming vulnerability
Linux Toolkit Theming vulnerability (CVE-2026-76023) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85892) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-84869). ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. CISA remediation due date: 2026-09-14. If you need help checking exposure, call (864) 335-9223.
Use after free in WebGL in Microsoft Edge vulnerability
Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-84352) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Dawn in Microsoft Edge vulnerability
Use after free in Dawn in Microsoft Edge vulnerability (CVE-2026-84333) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
UI misrepresentation in FullScreen in Microsoft Edge vulnerability
UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84330) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.