Skip to main content

Security Briefs

Page 99 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.

Showing page 99 (24 alerts) of 2651.

Actively exploited (KEV)Ransomware

CVE-2024-41713

Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-41713). Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-55956

Cleo Multiple Products Unauthenticated File Upload Vulnerability

Cleo Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55956). Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. CISA remediation due date: 2025-01-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-50623

Cleo Multiple Products Unrestricted File Upload Vulnerability

Cleo Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-50623). Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. CISA remediation due date: 2025-01-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-51378

CyberPanel Incorrect Default Permissions Vulnerability

CyberPersons CyberPanel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-51378). CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. CISA remediation due date: 2024-12-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-11667

Zyxel Multiple Firewalls Path Traversal Vulnerability

Zyxel Multiple Firewalls is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-11667). Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. CISA remediation due date: 2024-12-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-28461

Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

Array Networks AG/vxAG ArrayOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28461). Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. CISA remediation due date: 2024-12-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-9474

Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9474). Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators. CISA remediation due date: 2024-12-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-0012

Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-0012). Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. CISA remediation due date: 2024-12-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-49039

Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-49039). Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. CISA remediation due date: 2024-12-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-51567

CyberPanel Incorrect Default Permissions Vulnerability

CyberPersons CyberPanel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-51567). CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. CISA remediation due date: 2024-11-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-38094

Microsoft SharePoint Deserialization Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-38094). Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. CISA remediation due date: 2024-11-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-40711

Veeam Backup and Replication Deserialization Vulnerability

Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40711). Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. CISA remediation due date: 2024-11-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-9680

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9680). Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-30088

Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30088). Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0618

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0618). Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. CISA remediation due date: 2024-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-6670

Progress WhatsUp Gold SQL Injection Vulnerability

Progress WhatsUp Gold is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-6670). Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. CISA remediation due date: 2024-10-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-40766

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40766). SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-1000253

Linux Kernel PIE Stack Buffer Corruption Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-1000253). Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-23897

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins Jenkins Command Line Interface (CLI) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23897). Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. CISA remediation due date: 2024-09-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-37085

VMware ESXi Authentication Bypass Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-37085). VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. CISA remediation due date: 2024-08-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-23692

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23692). Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. CISA remediation due date: 2024-07-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-26169

Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-26169). Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. CISA remediation due date: 2024-07-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-4577

PHP-CGI OS Command Injection Vulnerability

PHP Group PHP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-4577). PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. CISA remediation due date: 2024-07-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-24919

Check Point Quantum Security Gateways Information Disclosure Vulnerability

Check Point Quantum Security Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-24919). Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.