Security Briefs
Page 68 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 22, 2026, 6:00 AM UTC.
Showing page 68 (24 alerts) of 2651.
Protect Your Property from Illegal Sales Through Parcel Owner Impersonation
Protect Your Property from Illegal Sales Through Parcel Owner Impersonation — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.
- Vendor:FBI IC3
the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c vulnerability
Linux-PAM Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. (CVE-2026-54411) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:Linux-PAM
- Product:Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory Joomla Content Editor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48907). Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. CISA remediation due date: 2026-06-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Dynamic Host Configuration Protocol (DHCP) Tampering vulnerability
Windows Dynamic Host Configuration Protocol (DHCP) Tampering vulnerability (CVE-2026-45602) was added to Microsoft’s security update guidance. Updated CWE value. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 (on-premises) Elevation of Privilege vulnerability
Microsoft Dynamics 365 (on-premises) Elevation of Privilege vulnerability (CVE-2026-40371) was added to Microsoft’s security update guidance. Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.… If you need help checking exposure, call (864) 335-9223.
Use after free in Tracing in Microsoft Edge vulnerability
Use after free in Tracing in Microsoft Edge vulnerability (CVE-2026-11701) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Bluetooth in Microsoft Edge vulnerability
Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-11700) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Bluetooth in Microsoft Edge vulnerability
Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-11699) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Microsoft Edge vulnerability (CVE-2026-11698) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Uninitialized Use in Video in Microsoft Edge vulnerability
Uninitialized Use in Video in Microsoft Edge vulnerability (CVE-2026-11697) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Inappropriate implementation in Passwords in Microsoft Edge vulnerability
Inappropriate implementation in Passwords in Microsoft Edge vulnerability (CVE-2026-11696) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in ServiceWorker in Microsoft Edge vulnerability
Use after free in ServiceWorker in Microsoft Edge vulnerability (CVE-2026-11695) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Inappropriate implementation in Plugins in Microsoft Edge vulnerability
Inappropriate implementation in Plugins in Microsoft Edge vulnerability (CVE-2026-11694) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Read Anything in Microsoft Edge vulnerability
Use after free in Read Anything in Microsoft Edge vulnerability (CVE-2026-11693) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in New Tab Page in Microsoft Edge vulnerability
Insufficient validation of untrusted input in New Tab Page in Microsoft Edge vulnerability (CVE-2026-11692) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds read and write in Media in Microsoft Edge vulnerability
Out of bounds read and write in Media in Microsoft Edge vulnerability (CVE-2026-11691) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Passwords in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Passwords in Microsoft Edge vulnerability (CVE-2026-11690) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Object lifecycle issue in SVG in Microsoft Edge vulnerability
Object lifecycle issue in SVG in Microsoft Edge vulnerability (CVE-2026-11689) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Dawn in Microsoft Edge vulnerability
Use after free in Dawn in Microsoft Edge vulnerability (CVE-2026-11688) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Dawn in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Dawn in Microsoft Edge vulnerability (CVE-2026-11687) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient data validation in MediaCapture in Microsoft Edge vulnerability
Insufficient data validation in MediaCapture in Microsoft Edge vulnerability (CVE-2026-11686) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient policy enforcement in Network in Microsoft Edge vulnerability
Insufficient policy enforcement in Network in Microsoft Edge vulnerability (CVE-2026-11685) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebCodecs in Microsoft Edge vulnerability
Use after free in WebCodecs in Microsoft Edge vulnerability (CVE-2026-11684) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Views in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Views in Microsoft Edge vulnerability (CVE-2026-11683) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.