Security Briefs
Page 78 of 90.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 78 (24 alerts) of 2139.
Windows Remote Desktop Services Remote Code Execution vulnerability
Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49123) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Denial of Service vulnerability
Windows Remote Desktop Services Denial of Service vulnerability (CVE-2024-49075) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2020-17103) was added to Microsoft’s security update guidance. To comprehensively address the vulnerability identified by CVE-2020-17103, Microsoft recommends installing the June 2026 updates for your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) for Android Spoofing vulnerability
Microsoft Edge (Chromium-based) for Android Spoofing vulnerability (CVE-2026-35429) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-33841) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Online Information Disclosure vulnerability
Microsoft Exchange Online Information Disclosure vulnerability (CVE-2026-48579) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Azure HorizonDB Elevation of Privilege vulnerability
Azure HorizonDB Elevation of Privilege vulnerability (CVE-2026-48567) was added to Microsoft’s security update guidance. Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Graph Information Disclosure vulnerability
Microsoft Graph Information Disclosure vulnerability (CVE-2026-47655) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-47644) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft M365 Copilot Remote Code Execution vulnerability
Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-45497) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Apache Thrift: C++ JSON OOB read vulnerability
Apache Thrift: C++ JSON OOB read vulnerability (CVE-2026-41607) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Apache Thrift: c_glib dispatch stack overflow vulnerability
Apache Thrift: c_glib dispatch stack overflow vulnerability (CVE-2026-41606) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
KDE KCoreAddons before 6.25 vulnerability
In In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection. (CVE-2026-41526) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:KDE
- Product:In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.
MIT Kerberos 5 (aka krb5) before 1.22.3 vulnerability
In In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. (CVE-2026-40356) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:MIT
- Product:In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
MIT Kerberos 5 (aka krb5) before 1.22.3 vulnerability
In In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message. (CVE-2026-40355) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:MIT
- Product:In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. vulnerability
An An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. (CVE-2026-37457) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
os in internal/syscall/unix vulnerability
os in internal/syscall/unix vulnerability (CVE-2026-32282) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. vulnerability
An An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. (CVE-2025-55551) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
tar in BusyBox through 1.37.0 vulnerability
In In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. (CVE-2025-46394) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
Go Go Snowflake Driver has race condition when checking access to Easy Logging configuration file (CVE-2025-46327) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
netstat in BusyBox through 1.37.0 vulnerability
In In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim. (CVE-2024-58251) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
SOAP apache:Map decoder with missing <value> vulnerability
SOAP apache:Map decoder with missing <value> vulnerability (CVE-2026-7262) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
php_mb_check_encoding() via mb_ereg_search_init() vulnerability
php_mb_check_encoding() via mb_ereg_search_init() vulnerability (CVE-2026-7259) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
SOAP using Apache map vulnerability
SOAP using Apache map vulnerability (CVE-2026-6722) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.