Security Briefs
Page 81 of 90.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 81 (24 alerts) of 2139.
net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work
net net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (CVE-2025-40003) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: phylink: add lock for serializing concurrent pl->phydev writes with resolver
net net: phylink: add lock for serializing concurrent pl->phydev writes with resolver (CVE-2025-39905) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
memcached before 1.6.42 vulnerability
In In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. (CVE-2026-47784) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
memcached before 1.6.42 vulnerability
In In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. (CVE-2026-47783) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: qrtr: ns: Limit the maximum server registration per node
net net: qrtr: ns: Limit the maximum server registration per node (CVE-2026-43491) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-40367) was added to Microsoft’s security update guidance. Today's changes were made in error and have been reverted. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
libexpat before 2.8.1 vulnerability
In In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. (CVE-2026-45186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Thrift: Node.js web_server.js multi-vulnerability
Apache Thrift: Node.js web_server.js multi-vulnerability (CVE-2026-43870) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability
Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability (CVE-2026-43869) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability (CVE-2026-43868) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
OCaml opam before 2.5.1 vulnerability
In In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. (CVE-2026-41082) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. vulnerability
An An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. (CVE-2026-37459) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Mbed TLS 3.x before 3.6.6 vulnerability
An An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. (CVE-2026-34876) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:Mbed
- Product:An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.
Mbed TLS through 3.6.5 and 4.x through 4.0.0 vulnerability
An An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. (CVE-2026-34874) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Mbed TLS 3.5.0 through 4.0.0 vulnerability
An An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. (CVE-2026-34873) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0 vulnerability
An An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). (CVE-2026-34872) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:Mbed
- Product:An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0 vulnerability
An An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). (CVE-2026-34871) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Mbed TLS through 4.0.0 vulnerability
In In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. (CVE-2025-66442) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability
Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability (CVE-2026-42822) was added to Microsoft’s security update guidance. Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams Spoofing vulnerability
Microsoft Teams Spoofing vulnerability (CVE-2026-32185) was added to Microsoft’s security update guidance. The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available. If you need help checking exposure, call (864) 335-9223.
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
CR CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 (CVE-2026-43968) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Entra ID Spoofing vulnerability
Azure Entra ID Spoofing vulnerability (CVE-2026-40379) was added to Microsoft’s security update guidance. Corrected CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Rich Text Edit Elevation of Privilege vulnerability
Windows Rich Text Edit Elevation of Privilege vulnerability (CVE-2026-32170) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Native WiFi Miniport Driver Remote Code Execution vulnerability
Windows Native WiFi Miniport Driver Remote Code Execution vulnerability (CVE-2026-32161) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.