Security Briefs
Page 72 of 141.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 7, 2026, 6:01 AM UTC.
Showing page 72 (24 alerts) of 3384.
Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability
Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability (CVE-2026-54123) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability
Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability (CVE-2026-50472) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Remote Code Execution vulnerability
Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-49179) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Azure Monitor Agent Elevation of Privilege vulnerability
Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-47299) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Information Disclosure vulnerability
Visual Studio Code Information Disclosure vulnerability (CVE-2026-47285) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability (CVE-2026-43871) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics Business Central Information Disclosure vulnerability
Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2026-40375) was added to Microsoft’s security update guidance. Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2026-40417) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics Business Central Information Disclosure vulnerability
Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2025-29821) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-38225) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability
Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability (CVE-2024-21380) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics Business Central Cross-site Scripting vulnerability
Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-40440) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics Business Central Cross-site Scripting vulnerability
Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-36946) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability
Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability (CVE-2021-34474) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability (CVE-2025-49506) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Spoofing vulnerability
Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-70332) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Azure Confidential Ledger Remote Code Execution vulnerability
Azure Confidential Ledger Remote Code Execution vulnerability (CVE-2026-68823) was added to Microsoft’s security update guidance. Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Purview eDiscovery Elevation of Privilege vulnerability
Microsoft Purview eDiscovery Elevation of Privilege vulnerability (CVE-2026-65668) was added to Microsoft’s security update guidance. Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams Elevation of Privilege vulnerability
Microsoft Teams Elevation of Privilege vulnerability (CVE-2026-65667) was added to Microsoft’s security update guidance. Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Azure SQL Database Elevation of Privilege vulnerability
Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-63522) was added to Microsoft’s security update guidance. Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams Spoofing vulnerability
Microsoft Teams Spoofing vulnerability (CVE-2026-62918) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams Elevation of Privilege vulnerability
Microsoft Teams Elevation of Privilege vulnerability (CVE-2026-62896) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft 365 Admin Center Elevation of Privilege vulnerability
Microsoft 365 Admin Center Elevation of Privilege vulnerability (CVE-2026-62873) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Azure Entra ID Spoofing vulnerability
Azure Entra ID Spoofing vulnerability (CVE-2026-62869) was added to Microsoft’s security update guidance. Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.