Security Briefs
Page 62 of 165.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 7, 2026, 6:01 AM UTC.
Showing page 62 (24 alerts) of 3939.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-66810) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Graphics Component Information Disclosure vulnerability
Microsoft Office Graphics Component Information Disclosure vulnerability (CVE-2026-66809) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-66808) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Graphics Component Remote Code Execution vulnerability
Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-66807) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-66806) was added to Microsoft’s security update guidance. Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-66805) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Cross Device Service Elevation of Privilege vulnerability
Microsoft Windows Cross Device Service Elevation of Privilege vulnerability (CVE-2026-66804) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Device Health Attestation (DHA) Remote Code Execution vulnerability
Windows Device Health Attestation (DHA) Remote Code Execution vulnerability (CVE-2026-66802) was added to Microsoft’s security update guidance. Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Key Guard Elevation of Privilege vulnerability
Windows Key Guard Elevation of Privilege vulnerability (CVE-2026-66799) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 (On-Premises) Information Disclosure vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure vulnerability (CVE-2026-66301) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-65815) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Storage Port Driver Elevation of Privilege vulnerability
Microsoft Windows Storage Port Driver Elevation of Privilege vulnerability (CVE-2026-65814) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Elevation of Privilege vulnerability
Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-65813) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-65807) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Azure CycleCloud Information Disclosure vulnerability
Azure CycleCloud Information Disclosure vulnerability (CVE-2026-65806) was added to Microsoft’s security update guidance. Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-65799) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-65798) was added to Microsoft’s security update guidance. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-65797) was added to Microsoft’s security update guidance. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Target Service Remote Code Execution vulnerability
Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65796) was added to Microsoft’s security update guidance. Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates table. These are i… If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-65795) was added to Microsoft’s security update guidance. No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows SMB Client Information Disclosure vulnerability
Windows SMB Client Information Disclosure vulnerability (CVE-2026-65794) was added to Microsoft’s security update guidance. Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Target Service Remote Code Execution vulnerability
Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65791) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Message Queuing Elevation of Privilege vulnerability
Windows Message Queuing Elevation of Privilege vulnerability (CVE-2026-65790) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-65789) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.