Skip to main content

Security Briefs

Page 57 of 165.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 7, 2026, 6:01 AM UTC.

Showing page 57 (24 alerts) of 3939.

Microsoft MSRC

CVE-2026-66309

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-66309) was added to Microsoft’s security update guidance. <p>Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65816

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-65816) was added to Microsoft’s security update guidance. <p>Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65801

Microsoft Exchange Online Elevation of Privilege vulnerability

Microsoft Exchange Online Elevation of Privilege vulnerability (CVE-2026-65801) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65770

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-65770) was added to Microsoft’s security update guidance. <p>Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63509

Microsoft Fabric Elevation of Privilege vulnerability

Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-63509) was added to Microsoft’s security update guidance. <p>Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62834

Azure Data Factory Elevation of Privilege vulnerability

Azure Data Factory Elevation of Privilege vulnerability (CVE-2026-62834) was added to Microsoft’s security update guidance. <p>Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55015

Microsoft Remote Help Denial of Service vulnerability

Microsoft Remote Help Denial of Service vulnerability (CVE-2026-55015) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55013

Windows Remote Help Defense Spoofing vulnerability

Windows Remote Help Defense Spoofing vulnerability (CVE-2026-55013) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54118

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-54118) was added to Microsoft’s security update guidance. The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54117

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-54117) was added to Microsoft’s security update guidance. The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58647

Microsoft PowerBI Report Server Spoofing vulnerability

Microsoft PowerBI Report Server Spoofing vulnerability (CVE-2026-58647) was added to Microsoft’s security update guidance. Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50383

Windows Print Spooler Information Disclosure vulnerability

Windows Print Spooler Information Disclosure vulnerability (CVE-2026-50383) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49798

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-49798) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42912

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-42912) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2021-26859

Microsoft Power BI Information Disclosure vulnerability

Microsoft Power BI Information Disclosure vulnerability (CVE-2021-26859) was added to Microsoft’s security update guidance. Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2020-1173

Microsoft Power BI Report Server Spoofing vulnerability

Microsoft Power BI Report Server Spoofing vulnerability (CVE-2020-1173) was added to Microsoft’s security update guidance. Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-65400

Apple macOS Improper Authentication Vulnerability

Apple macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-65400). Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. CISA remediation due date: 2026-08-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-59310

Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-59310). Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. CISA remediation due date: 2026-08-21. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56642

Microsoft Fabric Data Warehouse Remote Code Execution vulnerability

Microsoft Fabric Data Warehouse Remote Code Execution vulnerability (CVE-2026-56642) was added to Microsoft’s security update guidance. Updated the Security Updates table by removing an affected software entry. No user action is required. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-55040

Microsoft SharePoint Weak Authentication Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-55040). Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. CISA remediation due date: 2026-08-21. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50419

Windows Kernel Information Disclosure vulnerability

Windows Kernel Information Disclosure vulnerability (CVE-2026-50419) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47632

Azure Connected Machine Agent Elevation of Privilege vulnerability

Azure Connected Machine Agent Elevation of Privilege vulnerability (CVE-2026-47632) was added to Microsoft’s security update guidance. Corrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-33824

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-33824). Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. CISA remediation due date: 2026-08-21. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-24301

Microsoft Copilot Information Disclosure vulnerability

Microsoft Copilot Information Disclosure vulnerability (CVE-2026-24301) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.