Security Briefs
Page 98 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 98 (24 alerts) of 2651.
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20281). Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. CISA remediation due date: 2025-08-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Improper Authentication Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49706). Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49704). Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-53770). Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. CISA remediation due date: 2025-07-21. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC and Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-5777). Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. CISA remediation due date: 2025-07-11. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-6693). Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. CISA remediation due date: 2025-07-16. If you need help checking exposure, call (864) 335-9223.
SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-42999). SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. CISA remediation due date: 2025-06-05. If you need help checking exposure, call (864) 335-9223.
Langflow Missing Authentication Vulnerability
Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-3248). Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests. CISA remediation due date: 2025-05-26. If you need help checking exposure, call (864) 335-9223.
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31324). SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. CISA remediation due date: 2025-05-20. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-29824). Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2025-04-29. If you need help checking exposure, call (864) 335-9223.
CrushFTP Authentication Bypass Vulnerability
CrushFTP CrushFTP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31161). CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise. CISA remediation due date: 2025-04-28. If you need help checking exposure, call (864) 335-9223.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-22457). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. CISA remediation due date: 2025-04-11. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-24472). Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. CISA remediation due date: 2025-04-08. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-26633). Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. CISA remediation due date: 2025-04-01. If you need help checking exposure, call (864) 335-9223.
VMware ESXi Arbitrary Write Vulnerability
VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-22225). VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. CISA remediation due date: 2025-03-25. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8639). Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2025-03-24. If you need help checking exposure, call (864) 335-9223.
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-53704). SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. CISA remediation due date: 2025-03-11. If you need help checking exposure, call (864) 335-9223.
SimpleHelp Path Traversal Vulnerability
SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57727). SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. CISA remediation due date: 2025-03-06. If you need help checking exposure, call (864) 335-9223.
CyberoamOS (CROS) SQL Injection Vulnerability
Sophos CyberoamOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-29574). CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. CISA remediation due date: 2025-02-27. If you need help checking exposure, call (864) 335-9223.
SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-23006). SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands. CISA remediation due date: 2025-02-14. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55591). Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. CISA remediation due date: 2025-01-21. If you need help checking exposure, call (864) 335-9223.
Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-48365). Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. CISA remediation due date: 2025-02-03. If you need help checking exposure, call (864) 335-9223.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-0282). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. CISA remediation due date: 2025-01-15. If you need help checking exposure, call (864) 335-9223.
Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55550). Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.