Security Briefs
Page 80 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 80 (24 alerts) of 2651.
Heap buffer overflow in ANGLE in Microsoft Edge vulnerability
Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2026-10929) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebAppInstalls in Microsoft Edge vulnerability
Use after free in WebAppInstalls in Microsoft Edge vulnerability (CVE-2026-10923) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds write in GPU in Microsoft Edge vulnerability
Out of bounds write in GPU in Microsoft Edge vulnerability (CVE-2026-10892) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds write in ANGLE in Microsoft Edge vulnerability
Out of bounds write in ANGLE in Microsoft Edge vulnerability (CVE-2026-10883) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Denial of Service vulnerability
Windows Remote Desktop Services Denial of Service vulnerability (CVE-2025-21330) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Remote Code Execution vulnerability
Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49132) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Remote Code Execution vulnerability
Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49123) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Denial of Service vulnerability
Windows Remote Desktop Services Denial of Service vulnerability (CVE-2024-49075) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2020-17103) was added to Microsoft’s security update guidance. To comprehensively address the vulnerability identified by CVE-2020-17103, Microsoft recommends installing the June 2026 updates for your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-50751). Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. CISA remediation due date: 2026-06-11. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) for Android Spoofing vulnerability
Microsoft Edge (Chromium-based) for Android Spoofing vulnerability (CVE-2026-35429) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-33841) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
SolarWinds Serv-U is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-28318). SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. CISA remediation due date: 2026-06-19. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Online Information Disclosure vulnerability
Microsoft Exchange Online Information Disclosure vulnerability (CVE-2026-48579) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Azure HorizonDB Elevation of Privilege vulnerability
Azure HorizonDB Elevation of Privilege vulnerability (CVE-2026-48567) was added to Microsoft’s security update guidance. Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Graph Information Disclosure vulnerability
Microsoft Graph Information Disclosure vulnerability (CVE-2026-47655) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-47644) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft M365 Copilot Remote Code Execution vulnerability
Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-45497) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Apache Thrift: C++ JSON OOB read vulnerability
Apache Thrift: C++ JSON OOB read vulnerability (CVE-2026-41607) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Apache Thrift: c_glib dispatch stack overflow vulnerability
Apache Thrift: c_glib dispatch stack overflow vulnerability (CVE-2026-41606) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
KDE KCoreAddons before 6.25 vulnerability
In In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection. (CVE-2026-41526) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:KDE
- Product:In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.
MIT Kerberos 5 (aka krb5) before 1.22.3 vulnerability
In In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. (CVE-2026-40356) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:MIT
- Product:In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
MIT Kerberos 5 (aka krb5) before 1.22.3 vulnerability
In In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message. (CVE-2026-40355) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:MIT
- Product:In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. vulnerability
An An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. (CVE-2026-37457) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.