Skip to main content

Security Briefs

Page 73 of 165.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 7, 2026, 6:01 AM UTC.

Showing page 73 (24 alerts) of 3939.

Microsoft MSRC

CVE-2026-59132

Windows TCP/IP Denial of Service vulnerability

Windows TCP/IP Denial of Service vulnerability (CVE-2026-59132) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59128

Windows Encrypting File System (EFS) Information Disclosure vulnerability

Windows Encrypting File System (EFS) Information Disclosure vulnerability (CVE-2026-59128) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59127

Windows Installer Elevation of Privilege vulnerability

Windows Installer Elevation of Privilege vulnerability (CVE-2026-59127) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59126

Windows Event Logging Service Elevation of Privilege vulnerability

Windows Event Logging Service Elevation of Privilege vulnerability (CVE-2026-59126) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59124

Microsoft High Performance Computing (HPC) Pack Remote Code Execution vulnerability

Microsoft High Performance Computing (HPC) Pack Remote Code Execution vulnerability (CVE-2026-59124) was added to Microsoft’s security update guidance. Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59122

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-59122) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59113

Visual Studio Code Remote Code Execution vulnerability

Visual Studio Code Remote Code Execution vulnerability (CVE-2026-59113) was added to Microsoft’s security update guidance. Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58651

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-58651) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58650

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-58650) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58639

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-58639) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57105

Microsoft Office SharePoint Spoofing vulnerability

Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-57105) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56179

Windows Network Address Translation (NAT) Spoofing vulnerability

Windows Network Address Translation (NAT) Spoofing vulnerability (CVE-2026-56179) was added to Microsoft’s security update guidance. Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56174

Windows Narrator Braille Elevation of Privilege vulnerability

Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-56174) was added to Microsoft’s security update guidance. Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54984

Windows Imaging Component Remote Code Execution vulnerability

Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-54984) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54123

Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability

Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability (CVE-2026-54123) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50472

Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability

Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability (CVE-2026-50472) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49179

Windows Active Directory Domain Services Remote Code Execution vulnerability

Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-49179) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47299

Azure Monitor Agent Elevation of Privilege vulnerability

Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-47299) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47285

Visual Studio Code Information Disclosure vulnerability

Visual Studio Code Information Disclosure vulnerability (CVE-2026-47285) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43871

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability (CVE-2026-43871) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40375

Microsoft Dynamics Business Central Information Disclosure vulnerability

Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2026-40375) was added to Microsoft’s security update guidance. Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20349). Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. CISA remediation due date: 2026-08-14. If you need help checking exposure, call (864) 335-9223.

Industry news

Sexual Exploitation Actors Stealing and Leaking Explicit Content

Sexual Exploitation Actors Stealing and Leaking Explicit Content — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

  • Vendor:FBI IC3
Microsoft MSRC

CVE-2026-40417

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2026-40417) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.