Security Briefs
Page 92 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 92 (24 alerts) of 2651.
tse_start_xmit() vulnerability
net net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
chain mode vulnerability
net net: stmmac: fix integer underflow in chain mode (CVE-2026-31649) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
lan966x_fdma_rx_alloc_page_pool() vulnerability
net net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (CVE-2026-31646) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: lan966x: fix page pool leak in error paths
net net: lan966x: fix page pool leak in error paths (CVE-2026-31645) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
rx_complete() vulnerability
net net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (CVE-2026-31623) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled vulnerability
net net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-23381) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
the offload path vulnerability
net net/sched: ets: fix divide by zero in the offload path (CVE-2026-23379) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/sched: act_ife: Fix metalist update behavior vulnerability
net net/sched: act_ife: Fix metalist update behavior (CVE-2026-23378) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: phy: register phy led_triggers during probe to avoid AB-BA deadlock vulnerability
net net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (CVE-2026-23368) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: usb: kalmia: validate USB endpoints vulnerability
net net: usb: kalmia: validate USB endpoints (CVE-2026-23365) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check vulnerability
net net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check (CVE-2026-23447) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: usb: aqc111: Do not perform PM inside suspend callback vulnerability
net net: usb: aqc111: Do not perform PM inside suspend callback (CVE-2026-23446) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
buffer switching vulnerability
net net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs vulnerability
net net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (CVE-2026-23340) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung MagicINFO 9 Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-7399). Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.
SimpleHelp Path Traversal Vulnerability
SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57728). SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.
SimpleHelp Missing Authorization Vulnerability
SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57726). SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Microsoft Microsoft Entra ID Entitlement Management Spoofing (CVE-2026-35431) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Bing Remote Code Execution Vulnerability
Microsoft Microsoft Bing Remote Code Execution (CVE-2026-33819) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft 365 Copilot Elevation of Privilege Vulnerability
Microsoft Microsoft 365 Copilot Elevation of Privilege (CVE-2026-33102) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Dynamics 365 (online) Spoofing Vulnerability
Microsoft Microsoft Dynamics 365 (online) Spoofing (CVE-2026-32210) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Power Apps Remote Code Execution Vulnerability
Microsoft Microsoft Power Apps Remote Code Execution (CVE-2026-32172) was added to Microsoft’s security update guidance. Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
apple_report_fixup() vulnerability
apple_report_fixup() vulnerability (CVE-2026-31520) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer vulnerability
net net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.