Security Briefs
Page 83 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 83 (24 alerts) of 2651.
Microsoft SharePoint Remote Code Execution vulnerability
Microsoft SharePoint Remote Code Execution vulnerability (CVE-2026-45659) was added to Microsoft’s security update guidance. Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to tak… If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Remote Code Execution vulnerability
Microsoft Defender Remote Code Execution vulnerability (CVE-2026-45584) was added to Microsoft’s security update guidance. In the Security Updates table, added links to the Release Notes. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Denial of Service vulnerability
Microsoft Defender Denial of Service vulnerability (CVE-2026-45498) was added to Microsoft’s security update guidance. CWE added. Informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Elevation of Privilege vulnerability
Microsoft Defender Elevation of Privilege vulnerability (CVE-2026-41091) was added to Microsoft’s security update guidance. In the Security Updates table, added links to the Release Notes. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
rsync 3.0.1 through 3.4.1 vulnerability
In In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable. (CVE-2026-41035) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
- Vendor:rsync
- Product:In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
net/rds: handle zerocopy send cleanup before the message is queued
net net/rds: handle zerocopy send cleanup before the message is queued (CVE-2026-43502) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
net net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (CVE-2026-43496) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
net net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (CVE-2026-43495) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/rds: reset op_nents when zerocopy page pin fails
net net/rds: reset op_nents when zerocopy page pin fails (CVE-2026-43494) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
net net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (CVE-2026-43465) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ
net net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ (CVE-2026-43464) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-34336) was added to Microsoft’s security update guidance. The security impact for this CVE has been revised based on a re-assessment of the vulnerability. The original classification of Information Disclosure (ID) has been updated to Elevation of Privilege (EoP). If you need help checking exposure, call (864) 335-9223.
Azure SDK for Java Security Feature Bypass vulnerability
Azure SDK for Java Security Feature Bypass vulnerability (CVE-2026-33117) was added to Microsoft’s security update guidance. The executive summary has been updated to include additional details about this vulnerability. This change does not affect the available security updates. Customers should install the recommended updates to remain protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.
net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work
net net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (CVE-2025-40003) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: phylink: add lock for serializing concurrent pl->phydev writes with resolver
net net: phylink: add lock for serializing concurrent pl->phydev writes with resolver (CVE-2025-39905) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
memcached before 1.6.42 vulnerability
In In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. (CVE-2026-47784) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
memcached before 1.6.42 vulnerability
In In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. (CVE-2026-47783) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: qrtr: ns: Limit the maximum server registration per node
net net: qrtr: ns: Limit the maximum server registration per node (CVE-2026-43491) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-40367) was added to Microsoft’s security update guidance. Today's changes were made in error and have been reverted. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0806). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0249). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3459). Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft DirectX NULL Byte Overwrite Vulnerability
Microsoft DirectX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-1537). Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4250). Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.