Skip to main content

Security Briefs

Page 4 of 23.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 5, 2026, 6:01 AM UTC.

Showing page 4 (24 alerts) of 545.

Actively exploited (KEV)

CVE-2026-48907

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48907). Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. CISA remediation due date: 2026-06-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-54420

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed cPanel Plugin is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-54420). LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. CISA remediation due date: 2026-06-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-20262

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20262). Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. CISA remediation due date: 2026-06-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-35273). Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. CISA remediation due date: 2026-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-10520). Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. CISA remediation due date: 2026-06-14. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-7473

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-7473). Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. CISA remediation due date: 2026-06-23. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-20245

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20245). Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. CISA remediation due date: 2026-06-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-11645

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-11645). Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-06-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-50751

Check Point Security Gateway Improper Authentication Vulnerability

Check Point Security Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-50751). Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. CISA remediation due date: 2026-06-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-28318

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

SolarWinds Serv-U is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-28318). SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. CISA remediation due date: 2026-06-19. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-48595

Android Framework Integer Overflow Vulnerability

Android Framework is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-48595). Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. CISA remediation due date: 2026-06-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2022-0492

Linux Kernel Improper Authentication Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-0492). Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. CISA remediation due date: 2026-06-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-0257

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0257). Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. CISA remediation due date: 2026-06-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-48027

Nx Console Embedded Malicious Code Vulnerability

Nx Nx Console is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48027). Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. CISA remediation due date: 2026-06-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-45321

TanStack Unspecified Vulnerability

TanStack TanStack is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45321). TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. CISA remediation due date: 2026-06-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-45498

Microsoft Defender Denial of Service Vulnerability

Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45498). Microsoft Defender contains an unspecified vulnerability that allows for denial of service. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-41091

Microsoft Defender Link Following Vulnerability

Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-41091). Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2010-0806

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0806). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2010-0249

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0249). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2009-3459

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3459). Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2009-1537

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-1537). Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2008-4250

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4250). Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20182

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20182). Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. CISA remediation due date: 2026-05-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-6973

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-6973). Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. CISA remediation due date: 2026-05-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.