Skip to main content

Security Briefs

Page 92 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 92 (24 alerts) of 2651.

MediumMicrosoft MSRC

CVE-2026-31658

tse_start_xmit() vulnerability

net net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31649

chain mode vulnerability

net net: stmmac: fix integer underflow in chain mode (CVE-2026-31649) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31646

lan966x_fdma_rx_alloc_page_pool() vulnerability

net net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (CVE-2026-31646) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31645

net: lan966x: fix page pool leak in error paths

net net: lan966x: fix page pool leak in error paths (CVE-2026-31645) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31623

rx_complete() vulnerability

net net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (CVE-2026-31623) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23381

net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled vulnerability

net net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-23381) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23379

the offload path vulnerability

net net/sched: ets: fix divide by zero in the offload path (CVE-2026-23379) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23378

net/sched: act_ife: Fix metalist update behavior vulnerability

net net/sched: act_ife: Fix metalist update behavior (CVE-2026-23378) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23368

net: phy: register phy led_triggers during probe to avoid AB-BA deadlock vulnerability

net net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (CVE-2026-23368) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23365

net: usb: kalmia: validate USB endpoints vulnerability

net net: usb: kalmia: validate USB endpoints (CVE-2026-23365) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23447

net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check vulnerability

net net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check (CVE-2026-23447) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23446

net: usb: aqc111: Do not perform PM inside suspend callback vulnerability

net net: usb: aqc111: Do not perform PM inside suspend callback (CVE-2026-23446) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23438

buffer switching vulnerability

net net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-23340

net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs vulnerability

net net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (CVE-2026-23340) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2024-7399

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-7399). Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-57728

SimpleHelp Path Traversal Vulnerability

SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57728). SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-57726

SimpleHelp Missing Authorization Vulnerability

SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57726). SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-35431

Microsoft Entra ID Entitlement Management Spoofing Vulnerability

Microsoft Microsoft Entra ID Entitlement Management Spoofing (CVE-2026-35431) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33819

Microsoft Bing Remote Code Execution Vulnerability

Microsoft Microsoft Bing Remote Code Execution (CVE-2026-33819) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33102

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Microsoft Microsoft 365 Copilot Elevation of Privilege (CVE-2026-33102) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32210

Microsoft Dynamics 365 (online) Spoofing Vulnerability

Microsoft Microsoft Dynamics 365 (online) Spoofing (CVE-2026-32210) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32172

Microsoft Power Apps Remote Code Execution Vulnerability

Microsoft Microsoft Power Apps Remote Code Execution (CVE-2026-32172) was added to Microsoft’s security update guidance. Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31520

apple_report_fixup() vulnerability

apple_report_fixup() vulnerability (CVE-2026-31520) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-31507

net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer vulnerability

net net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.