Security Briefs
Page 99 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 99 (24 alerts) of 2651.
Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-41713). Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.
Cleo Multiple Products Unauthenticated File Upload Vulnerability
Cleo Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55956). Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. CISA remediation due date: 2025-01-07. If you need help checking exposure, call (864) 335-9223.
Cleo Multiple Products Unrestricted File Upload Vulnerability
Cleo Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-50623). Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. CISA remediation due date: 2025-01-03. If you need help checking exposure, call (864) 335-9223.
CyberPanel Incorrect Default Permissions Vulnerability
CyberPersons CyberPanel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-51378). CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. CISA remediation due date: 2024-12-25. If you need help checking exposure, call (864) 335-9223.
Zyxel Multiple Firewalls Path Traversal Vulnerability
Zyxel Multiple Firewalls is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-11667). Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. CISA remediation due date: 2024-12-24. If you need help checking exposure, call (864) 335-9223.
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Array Networks AG/vxAG ArrayOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28461). Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. CISA remediation due date: 2024-12-16. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9474). Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators. CISA remediation due date: 2024-12-09. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-0012). Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. CISA remediation due date: 2024-12-09. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-49039). Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. CISA remediation due date: 2024-12-03. If you need help checking exposure, call (864) 335-9223.
CyberPanel Incorrect Default Permissions Vulnerability
CyberPersons CyberPanel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-51567). CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. CISA remediation due date: 2024-11-28. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Deserialization Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-38094). Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. CISA remediation due date: 2024-11-12. If you need help checking exposure, call (864) 335-9223.
Veeam Backup and Replication Deserialization Vulnerability
Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40711). Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. CISA remediation due date: 2024-11-07. If you need help checking exposure, call (864) 335-9223.
Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9680). Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30088). Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Microsoft SQL Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0618). Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. CISA remediation due date: 2024-10-09. If you need help checking exposure, call (864) 335-9223.
Progress WhatsUp Gold SQL Injection Vulnerability
Progress WhatsUp Gold is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-6670). Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. CISA remediation due date: 2024-10-07. If you need help checking exposure, call (864) 335-9223.
SonicWall SonicOS Improper Access Control Vulnerability
SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40766). SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-1000253). Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Jenkins Jenkins Command Line Interface (CLI) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23897). Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. CISA remediation due date: 2024-09-09. If you need help checking exposure, call (864) 335-9223.
VMware ESXi Authentication Bypass Vulnerability
VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-37085). VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. CISA remediation due date: 2024-08-20. If you need help checking exposure, call (864) 335-9223.
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Rejetto HTTP File Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23692). Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. CISA remediation due date: 2024-07-30. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-26169). Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. CISA remediation due date: 2024-07-04. If you need help checking exposure, call (864) 335-9223.
PHP-CGI OS Command Injection Vulnerability
PHP Group PHP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-4577). PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. CISA remediation due date: 2024-07-03. If you need help checking exposure, call (864) 335-9223.
Check Point Quantum Security Gateways Information Disclosure Vulnerability
Check Point Quantum Security Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-24919). Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.