Skip to main content

Security Briefs

Page 91 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 91 (24 alerts) of 2651.

Actively exploited (KEV)

CVE-2026-0300

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0300). Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. CISA remediation due date: 2026-05-09. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-3184

Util-linux: util-linux: access control bypass due to improper hostname canonicalization vulnerability

Util-linux: util-linux: access control bypass due to improper hostname canonicalization vulnerability (CVE-2026-3184) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31533

-EBUSY error path of tls_do_encryption vulnerability

net net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-31431

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-31431). Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. CISA remediation due date: 2026-05-15. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-27456

util-linux mount(8) - Loop Device Setup vulnerability

util-linux mount(8) - Loop Device Setup vulnerability (CVE-2026-27456) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2026-41940

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM and WP2 (WordPress Squared) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-41940). WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. CISA remediation due date: 2026-05-03. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41604

Apache Thrift: Swift Range crash in skip()

Apache Apache Thrift: Swift Range crash in skip() (CVE-2026-41604) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34481

JsonTemplateLayout vulnerability

Apache Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout (CVE-2026-34481) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34480

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

Apache Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34480) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34479

Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters vulnerability

Apache Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34479) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34477

TLS configuration vulnerability

Apache Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass (CVE-2026-34477) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-3298

Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability

Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability (CVE-2026-3298) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31546

bond_debug_rlb_hash_show vulnerability

net net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31508

net: openvswitch: Avoid releasing netdev before teardown completes vulnerability

net net: openvswitch: Avoid releasing netdev before teardown completes (CVE-2026-31508) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31429

net: skb: fix cross-cache free of KFENCE-allocated skb head vulnerability

net net: skb: fix cross-cache free of KFENCE-allocated skb head (CVE-2026-31429) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31563

net: macb: Use dev_consume_skb_any() to free TX SKBs vulnerability

net net: macb: Use dev_consume_skb_any() to free TX SKBs (CVE-2026-31563) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-21246

Windows Graphics Component Elevation of Privilege Vulnerability

Microsoft Windows Graphics Component Elevation of Privilege (CVE-2026-21246) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33103

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Microsoft Microsoft Dynamics 365 (On-Premises) Information Disclosure (CVE-2026-33103) was added to Microsoft’s security update guidance. Added acknowledgements. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2024-1708

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1708). ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. CISA remediation due date: 2026-05-12. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-26149

Microsoft Power Apps Desktop Client Spoofing Vulnerability

Microsoft Microsoft Power Apps Desktop Client Spoofing (CVE-2026-26149) was added to Microsoft’s security update guidance. CVE-2026-26149 Microsoft Power Apps Desktop Client Spoofing Vulnerability PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31684

net: sched: act_csum: validate nested VLAN headers vulnerability

net net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31680

net: ipv6: flowlabel: defer exclusive option free until RCU teardown vulnerability

net net: ipv6: flowlabel: defer exclusive option free until RCU teardown (CVE-2026-31680) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31675

packet corruption vulnerability

net net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31670

net: rfkill: prevent unlimited numbers of rfkill events from being created vulnerability

net net: rfkill: prevent unlimited numbers of rfkill events from being created (CVE-2026-31670) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.