Skip to main content

Security Briefs

Page 72 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 72 (24 alerts) of 2651.

Microsoft MSRC

CVE-2026-48913

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted vulnerability

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted vulnerability (CVE-2026-48913) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-44631

Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow

Apache Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow (CVE-2026-44631) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44186

Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp

Apache Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp (CVE-2026-44186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44185

Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`

Apache Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (CVE-2026-44185) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44119

Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules

Apache Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules (CVE-2026-44119) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43951

Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash

Apache Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash (CVE-2026-43951) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42536

Apache HTTP Server: mod_xml2enc heap overflow vulnerability

Apache HTTP Server: mod_xml2enc heap overflow vulnerability (CVE-2026-42536) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42535

Apache HTTP Server: mod_dav_fs protected directory access vulnerability

Apache HTTP Server: mod_dav_fs protected directory access vulnerability (CVE-2026-42535) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34356

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow vulnerability

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow vulnerability (CVE-2026-34356) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34355

Apache HTTP Server: mod_proxy_html buffer overflow vulnerability

Apache HTTP Server: mod_proxy_html buffer overflow vulnerability (CVE-2026-34355) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-29170

Apache HTTP Server: mod_proxy_ftp XSS vulnerability

Apache HTTP Server: mod_proxy_ftp XSS vulnerability (CVE-2026-29170) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-29167

Apache HTTP Server: mod_ldap per-dir use-after-free vulnerability

Apache HTTP Server: mod_ldap per-dir use-after-free vulnerability (CVE-2026-29167) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-10520). Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. CISA remediation due date: 2026-06-14. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-48569

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-48569) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47298

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47298) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47294

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47294) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-46319

net/sched: act_ct: Only release RCU read lock after ct_ft

net net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-46287

net: txgbe: fix RTNL assertion warning when remove module

net net: txgbe: fix RTNL assertion warning when remove module (CVE-2026-46287) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-45482

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability (CVE-2026-45482) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number and Title as the Chat extention is now merged into Visual Studio Code If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40376

Visual Studio Code Elevation of Privilege vulnerability

Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-40376) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-7473

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-7473). Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. CISA remediation due date: 2026-06-23. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50512

Microsoft PC Manager Elevation of Privilege vulnerability

Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-50512) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50511

Microsoft PC Manager Elevation of Privilege vulnerability

Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-50511) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50508

Windows NTLM Spoofing vulnerability

Windows NTLM Spoofing vulnerability (CVE-2026-50508) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.