Security Briefs
Page 4 of 165.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.
Showing page 4 (24 alerts) of 3939.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-77490) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Terminal Remote Code Execution vulnerability
Windows Terminal Remote Code Execution vulnerability (CVE-2026-54124) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-54112) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Search Service Elevation of Privilege vulnerability
Windows Search Service Elevation of Privilege vulnerability (CVE-2026-50679) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Media Elevation of Privilege vulnerability
Windows Media Elevation of Privilege vulnerability (CVE-2026-50676) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Out of bounds read in V8 in Microsoft Edge vulnerability
Out of bounds read in V8 in Microsoft Edge vulnerability (CVE-2025-2137) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Type Confusion in V8 in Microsoft Edge vulnerability
Type Confusion in V8 in Microsoft Edge vulnerability (CVE-2025-1920) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-87491). Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-09-23. If you need help checking exposure, call (864) 335-9223.
Windows Partition Management Driver Elevation of Privilege vulnerability
Windows Partition Management Driver Elevation of Privilege vulnerability (CVE-2026-69492) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure OpenAI Elevation of Privilege vulnerability
Azure OpenAI Elevation of Privilege vulnerability (CVE-2026-45499) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20079). Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. CISA remediation due date: 2026-09-12. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-19490). Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. CISA remediation due date: 2026-09-12. If you need help checking exposure, call (864) 335-9223.
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-25249). Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. CISA remediation due date: 2026-09-12. If you need help checking exposure, call (864) 335-9223.
N-able N-central Static Code Injection Vulnerability
N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-86218). N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. CISA remediation due date: 2026-09-11. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-85880). Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. CISA remediation due date: 2026-09-22. If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Remote Code Execution vulnerability
Windows Print Spooler Remote Code Execution vulnerability (CVE-2026-85877) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Excel Information Disclosure vulnerability
Microsoft Office Excel Information Disclosure vulnerability (CVE-2026-85875) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-85360) was added to Microsoft’s security update guidance. <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Information leak in Skia in Microsoft Edge vulnerability
Information leak in Skia in Microsoft Edge vulnerability (CVE-2026-84359) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Improper privilege management in Downloads in Microsoft Edge vulnerability
Improper privilege management in Downloads in Microsoft Edge vulnerability (CVE-2026-84358) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Improper input validation in Omnibox in Microsoft Edge vulnerability
Improper input validation in Omnibox in Microsoft Edge vulnerability (CVE-2026-84357) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
UI misrepresentation in FullScreen in Microsoft Edge vulnerability
UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84356) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in Navigation in Microsoft Edge vulnerability
Incorrect authorization in Navigation in Microsoft Edge vulnerability (CVE-2026-84355) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in FileSystem in Microsoft Edge vulnerability
Incorrect authorization in FileSystem in Microsoft Edge vulnerability (CVE-2026-84354) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.