Skip to main content

Security Briefs

Page 81 of 90.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 81 (24 alerts) of 2139.

Microsoft MSRC

CVE-2025-40003

net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work

net net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (CVE-2025-40003) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2025-39905

net: phylink: add lock for serializing concurrent pl->phydev writes with resolver

net net: phylink: add lock for serializing concurrent pl->phydev writes with resolver (CVE-2025-39905) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-47784

memcached before 1.6.42 vulnerability

In In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. (CVE-2026-47784) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-47783

memcached before 1.6.42 vulnerability

In In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. (CVE-2026-47783) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43491

net: qrtr: ns: Limit the maximum server registration per node

net net: qrtr: ns: Limit the maximum server registration per node (CVE-2026-43491) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-40367

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-40367) was added to Microsoft’s security update guidance. Today's changes were made in error and have been reverted. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45186

libexpat before 2.8.1 vulnerability

In In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. (CVE-2026-45186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43870

Apache Thrift: Node.js web_server.js multi-vulnerability

Apache Thrift: Node.js web_server.js multi-vulnerability (CVE-2026-43870) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43869

Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability

Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability (CVE-2026-43869) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43868

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability (CVE-2026-43868) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41082

OCaml opam before 2.5.1 vulnerability

In In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. (CVE-2026-41082) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-37459

FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. vulnerability

An An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. (CVE-2026-37459) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34876

Mbed TLS 3.x before 3.6.6 vulnerability

An An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. (CVE-2026-34876) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-34874

Mbed TLS through 3.6.5 and 4.x through 4.0.0 vulnerability

An An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. (CVE-2026-34874) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34873

Mbed TLS 3.5.0 through 4.0.0 vulnerability

An An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. (CVE-2026-34873) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34872

Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0 vulnerability

An An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). (CVE-2026-34872) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34871

Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0 vulnerability

An An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). (CVE-2026-34871) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-66442

Mbed TLS through 4.0.0 vulnerability

In In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. (CVE-2025-66442) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42822

Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability

Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability (CVE-2026-42822) was added to Microsoft’s security update guidance. Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32185

Microsoft Teams Spoofing vulnerability

Microsoft Teams Spoofing vulnerability (CVE-2026-32185) was added to Microsoft’s security update guidance. The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43968

CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1

CR CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 (CVE-2026-43968) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-40379

Azure Entra ID Spoofing vulnerability

Azure Entra ID Spoofing vulnerability (CVE-2026-40379) was added to Microsoft’s security update guidance. Corrected CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32170

Windows Rich Text Edit Elevation of Privilege vulnerability

Windows Rich Text Edit Elevation of Privilege vulnerability (CVE-2026-32170) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32161

Windows Native WiFi Miniport Driver Remote Code Execution vulnerability

Windows Native WiFi Miniport Driver Remote Code Execution vulnerability (CVE-2026-32161) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.