Security Briefs
Page 8 of 21.
Alerts tracked
2625
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.
Showing page 8 (24 alerts) of 503.
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-38352). Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. CISA remediation due date: 2025-09-25. If you need help checking exposure, call (864) 335-9223.
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
TP-Link Multiple Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-9377). TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-24. If you need help checking exposure, call (864) 335-9223.
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link TL-WR841N is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-50224). TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-24. If you need help checking exposure, call (864) 335-9223.
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
TP-Link TL-WA855RE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-24363). TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-23. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler Memory Overflow Vulnerability
Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-7775). Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. CISA remediation due date: 2025-08-28. If you need help checking exposure, call (864) 335-9223.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8069). Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.
Citrix Session Recording Improper Privilege Management Vulnerability
Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8068). Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-43300). Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. CISA remediation due date: 2025-09-11. If you need help checking exposure, call (864) 335-9223.
N-able N-Central Command Injection Vulnerability
N-able N-Central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8876). N-able N-Central contains a command injection vulnerability via improper sanitization of user input. CISA remediation due date: 2025-08-20. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
N-able N-Central Insecure Deserialization Vulnerability
N-able N-Central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8875). N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. CISA remediation due date: 2025-08-20. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
RARLAB WinRAR Path Traversal Vulnerability
RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8088). RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. CISA remediation due date: 2025-09-02. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Resource Management Errors Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-3893). Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-02. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Excel Remote Code Execution Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2007-0671). Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system. CISA remediation due date: 2025-09-02. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20337). Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. CISA remediation due date: 2025-08-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20281). Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. CISA remediation due date: 2025-08-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Improper Authentication Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49706). Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49704). Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-53770). Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. CISA remediation due date: 2025-07-21. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC and Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-5777). Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. CISA remediation due date: 2025-07-11. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-6693). Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. CISA remediation due date: 2025-07-16. If you need help checking exposure, call (864) 335-9223.
SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-42999). SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. CISA remediation due date: 2025-06-05. If you need help checking exposure, call (864) 335-9223.
Langflow Missing Authentication Vulnerability
Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-3248). Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests. CISA remediation due date: 2025-05-26. If you need help checking exposure, call (864) 335-9223.
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31324). SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. CISA remediation due date: 2025-05-20. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-29824). Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2025-04-29. If you need help checking exposure, call (864) 335-9223.