Skip to main content

Security Briefs

Page 97 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 97 (24 alerts) of 2651.

Actively exploited (KEV)

CVE-2011-3402

Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2011-3402). Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2010-3962

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-3962). Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2010-3765

Mozilla Multiple Products Remote Code Execution Vulnerability

Mozilla Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-3765). Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-21043

Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung Mobile Devices is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-21043). Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. CISA remediation due date: 2025-10-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20352

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco IOS and IOS XE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20352). Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. CISA remediation due date: 2025-10-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-10035

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-10035). Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. CISA remediation due date: 2025-10-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20362

Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20362). Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333. CISA remediation due date: 2025-09-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20333

Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20333). Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362. CISA remediation due date: 2025-09-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-10585

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-10585). Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CISA remediation due date: 2025-10-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-48543

Android Runtime Use-After-Free Vulnerability

Android Runtime is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-48543). Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. CISA remediation due date: 2025-09-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-38352

Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-38352). Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. CISA remediation due date: 2025-09-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-9377

TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability

TP-Link Multiple Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-9377). TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2023-50224

TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

TP-Link TL-WR841N is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-50224). TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2020-24363

TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

TP-Link TL-WA855RE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-24363). TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-7775

Citrix NetScaler Memory Overflow Vulnerability

Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-7775). Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. CISA remediation due date: 2025-08-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2024-8069

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8069). Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2024-8068

Citrix Session Recording Improper Privilege Management Vulnerability

Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8068). Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-43300

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-43300). Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. CISA remediation due date: 2025-09-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-8876

N-able N-Central Command Injection Vulnerability

N-able N-Central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8876). N-able N-Central contains a command injection vulnerability via improper sanitization of user input. CISA remediation due date: 2025-08-20. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2025-8875

N-able N-Central Insecure Deserialization Vulnerability

N-able N-Central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8875). N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. CISA remediation due date: 2025-08-20. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8088). RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. CISA remediation due date: 2025-09-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2013-3893

Microsoft Internet Explorer Resource Management Errors Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-3893). Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-09-02. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2007-0671

Microsoft Office Excel Remote Code Execution Vulnerability

Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2007-0671). Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system. CISA remediation due date: 2025-09-02. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20337). Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. CISA remediation due date: 2025-08-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.