Security Briefs
Page 41 of 165.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.
Showing page 41 (24 alerts) of 3939.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66819) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66818) was added to Microsoft’s security update guidance. <p>Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Security Feature Bypass vulnerability
Microsoft SQL Server Security Feature Bypass vulnerability (CVE-2026-66816) was added to Microsoft’s security update guidance. <p>Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66814) was added to Microsoft’s security update guidance. <p>Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business and Lync Denial of Service vulnerability
Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66308) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business and Lync Denial of Service vulnerability
Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66307) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business Information Disclosure vulnerability
Skype for Business Information Disclosure vulnerability (CVE-2026-66306) was added to Microsoft’s security update guidance. <p>Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business Spoofing vulnerability
Skype for Business Spoofing vulnerability (CVE-2026-66305) was added to Microsoft’s security update guidance. Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Skype for Business Information Disclosure vulnerability
Skype for Business Information Disclosure vulnerability (CVE-2026-66304) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business and Lync Denial of Service vulnerability
Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66303) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business Remote Code Execution vulnerability
Skype for Business Remote Code Execution vulnerability (CVE-2026-66302) was added to Microsoft’s security update guidance. <p>External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Teams for Android Information Disclosure vulnerability
Microsoft Teams for Android Information Disclosure vulnerability (CVE-2026-65812) was added to Microsoft’s security update guidance. Corrected fix build number. Informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-65772) was added to Microsoft’s security update guidance. <p>Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-65669) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Spoofing vulnerability
Microsoft Office Spoofing vulnerability (CVE-2026-64918) was added to Microsoft’s security update guidance. Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Skype for Business Spoofing vulnerability
Skype for Business Spoofing vulnerability (CVE-2026-63523) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Entra ID Elevation of Privilege vulnerability
Microsoft Entra ID Elevation of Privilege vulnerability (CVE-2026-62916) was added to Microsoft’s security update guidance. <p>Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Discovery Studio Information Disclosure vulnerability
Microsoft Discovery Studio Information Disclosure vulnerability (CVE-2026-62906) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Arc SQL Server Extension Elevation of Privilege vulnerability
Azure Arc SQL Server Extension Elevation of Privilege vulnerability (CVE-2026-62895) was added to Microsoft’s security update guidance. <p>Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Remote Code Execution vulnerability
Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-62813) was added to Microsoft’s security update guidance. Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-62804) was added to Microsoft’s security update guidance. External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft PowerShell Security Feature Bypass vulnerability
Microsoft PowerShell Security Feature Bypass vulnerability (CVE-2026-62801) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Denial of Service vulnerability
Windows Active Directory Domain Services Denial of Service vulnerability (CVE-2026-62762) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Windows Netlogon Spoofing vulnerability
Windows Netlogon Spoofing vulnerability (CVE-2026-62759) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.</p> If you need help checking exposure, call (864) 335-9223.