<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PremierePC Security Briefs</title><description>Published CVE security briefs and CISA KEV alerts tracked by PremierePC.</description><link>https://premierepc.com/security-briefs</link><language>en-us</language><atom:link href="https://premierepc.com/security-briefs/rss.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-18556</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-18556</guid><description>N-able N-central is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an </description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>N-able</category><category>N-central</category><category>CISA KEV</category></item><item><title>CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-34486</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-34486</guid><description>Apache Tomcat is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data v</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>Tomcat</category><category>CISA KEV</category></item><item><title>Ongoing Threats of Swatting and Indicators for Community Members</title><link>https://premierepc.com/security-briefs/news-260804</link><guid isPermaLink="true">https://premierepc.com/security-briefs/news-260804</guid><description>Ongoing Threats of Swatting and Indicators for Community Members — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for</description><pubDate>Tue, 04 Aug 2026 12:00:00 GMT</pubDate><category>FBI IC3</category><category>Industry news</category></item><item><title>CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-18577</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-18577</guid><description>N-able N-central is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-18577). N-able N-central contains an authentication bypass using an </description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>N-able</category><category>N-central</category><category>CISA KEV</category></item><item><title>CVE-2026-50341: Windows NTFS Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50341</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50341</guid><description>Windows NTFS Information Disclosure vulnerability (CVE-2026-50341) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tr</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows NTFS Information Disclosure</category></item><item><title>CVE-2026-24304: Azure Resource Manager Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-24304</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-24304</guid><description>Azure Resource Manager Elevation of Privilege vulnerability (CVE-2026-24304) was added to Microsoft’s security update guidance. Informational Change. CVE I</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Resource Manager Elevation of Privilege</category></item><item><title>CVE-2026-54128: Windows DHCP Client Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-54128</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-54128</guid><description>Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-54128) was added to Microsoft’s security update guidance. Updated an acknowledgement. Thi</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows DHCP Client Remote Code Execution</category></item><item><title>CVE-2026-55129: Microsoft Office Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-55129</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-55129</guid><description>Microsoft Office Remote Code Execution vulnerability (CVE-2026-55129) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Office Remote Code Execution</category></item><item><title>CVE-2026-56197: Windows Admin Center (WAC) Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56197</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56197</guid><description>Windows Admin Center (WAC) Remote Code Execution vulnerability (CVE-2026-56197) was added to Microsoft’s security update guidance. Updated an acknowledgeme</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Admin Center (WAC) Remote Code Execution</category></item><item><title>CVE-2026-66803: Azure Cosmos DB Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-66803</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-66803</guid><description>Azure Cosmos DB Remote Code Execution vulnerability (CVE-2026-66803) was added to Microsoft’s security update guidance. Improper access control in Azure Co</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Cosmos DB Remote Code Execution</category></item><item><title>Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions</title><link>https://premierepc.com/security-briefs/news-260730</link><guid isPermaLink="true">https://premierepc.com/security-briefs/news-260730</guid><description>Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions — FBI IC3 indu</description><pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate><category>FBI IC3</category><category>Industry news</category></item><item><title>CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-20316</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-20316</guid><description>Cisco Secure Firewall Management Center (FMC) is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-20316). Cisco Secure Firewall Managemen</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Secure Firewall Management Center (FMC)</category><category>CISA KEV</category></item><item><title>CVE-2026-50422: Windows NTFS Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50422</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50422</guid><description>Windows NTFS Elevation of Privilege vulnerability (CVE-2026-50422) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is a</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows NTFS Elevation of Privilege</category></item><item><title>CVE-2026-59117: Windows Terminal Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-59117</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-59117</guid><description>Windows Terminal Remote Code Execution vulnerability (CVE-2026-59117) was added to Microsoft’s security update guidance. Change the name of the affected so</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Terminal Remote Code Execution</category></item><item><title>CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2025-68686</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2025-68686</guid><description>Fortinet FortiOS is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2025-68686). Fortinet FortiOS contains an exposure of sensitive informati</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiOS</category><category>CISA KEV</category></item><item><title>CVE-2026-50333: Windows Spaceport.sys Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50333</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50333</guid><description>Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-50333) was added to Microsoft’s security update guidance. Updated an acknowledgement. </description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Spaceport.sys Elevation of Privilege</category></item><item><title>CVE-2026-50343: Microsoft Install Service Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50343</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50343</guid><description>Microsoft Install Service Elevation of Privilege vulnerability (CVE-2026-50343) was added to Microsoft’s security update guidance. Updated an acknowledgeme</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Install Service Elevation of Privilege</category></item><item><title>CVE-2026-50697: Windows Common Log File System Driver Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50697</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50697</guid><description>Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-50697) was added to Microsoft’s security update guidance. Updated an a</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Common Log File System Driver Elevation of Privilege</category></item><item><title>CVE-2026-48561: Microsoft Edge Copilot Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-48561</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-48561</guid><description>Microsoft Edge Copilot Remote Code Execution vulnerability (CVE-2026-48561) was added to Microsoft’s security update guidance. Corrected the CVE descriptio</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Edge Copilot Remote Code Execution</category></item><item><title>CVE-2026-62835: Azure Portal Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-62835</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-62835</guid><description>Azure Portal Information Disclosure vulnerability (CVE-2026-62835) was added to Microsoft’s security update guidance. Corrected the CVE description and tit</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Portal Information Disclosure</category></item><item><title>CVE-2026-35425: Azure API Management (APIM) Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-35425</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-35425</guid><description>Azure API Management (APIM) Remote Code Execution vulnerability (CVE-2026-35425) was added to Microsoft’s security update guidance. Improper access control</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure API Management (APIM) Remote Code Execution</category></item><item><title>CVE-2026-49159: Microsoft Graph Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-49159</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-49159</guid><description>Microsoft Graph Information Disclosure vulnerability (CVE-2026-49159) was added to Microsoft’s security update guidance. Exposure of sensitive information </description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Graph Information Disclosure</category></item><item><title>CVE-2026-50046: an error path when a DoT forwarded query is jostled out vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50046</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50046</guid><description>an error path when a DoT forwarded query is jostled out vulnerability (CVE-2026-50046) was added to Microsoft’s security update guidance. Information publi</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>an</category><category>an error path when a DoT forwarded query is jostled out</category></item><item><title>CVE-2026-50517: Microsoft M365 Copilot Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50517</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50517</guid><description>Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-50517) was added to Microsoft’s security update guidance. Deserialization of untrusted</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft M365 Copilot Remote Code Execution</category></item><item><title>CVE-2026-54120: Microsoft Surface Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-54120</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-54120</guid><description>Microsoft Surface Remote Code Execution vulnerability (CVE-2026-54120) was added to Microsoft’s security update guidance. Improper input validation in Micr</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Surface Remote Code Execution</category></item><item><title>CVE-2026-56160: Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56160</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56160</guid><description>Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability (CVE-2026-56160) was added to Microsoft’s security update guidance. Improper authorizati</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Red Hat OpenShift (ARO) Elevation of Privilege</category></item><item><title>CVE-2026-56163: Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56163</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56163</guid><description>Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-56163) was added to Microsoft’s security update guidance. Missing authent</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Azure Kubernetes Service Elevation of Privilege</category></item><item><title>CVE-2026-56165: Microsoft Account Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56165</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56165</guid><description>Microsoft Account Remote Code Execution vulnerability (CVE-2026-56165) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Mic</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Account Remote Code Execution</category></item><item><title>CVE-2026-56167: Azure AI Search Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56167</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56167</guid><description>Azure AI Search Elevation of Privilege vulnerability (CVE-2026-56167) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure AI Search Elevation of Privilege</category></item><item><title>CVE-2026-56191: Microsoft Exchange Online Tampering vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56191</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56191</guid><description>Microsoft Exchange Online Tampering vulnerability (CVE-2026-56191) was added to Microsoft’s security update guidance. Improper authentication in Microsoft </description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Exchange Online Tampering</category></item><item><title>CVE-2026-58275: Azure DNS Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-58275</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-58275</guid><description>Azure DNS Elevation of Privilege vulnerability (CVE-2026-58275) was added to Microsoft’s security update guidance. Missing authorization in Azure DNS allow</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure DNS Elevation of Privilege</category></item><item><title>CVE-2026-58630: Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-58630</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-58630</guid><description>Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability (CVE-2026-58630) was added to Microsoft’s security update guidance. Improper acce</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure App Service on Azure Stack Hub Elevation of Privilege</category></item><item><title>CVE-2026-62825: Azure Key Vault Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-62825</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-62825</guid><description>Azure Key Vault Elevation of Privilege vulnerability (CVE-2026-62825) was added to Microsoft’s security update guidance. Improper authentication in Azure K</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Key Vault Elevation of Privilege</category></item><item><title>CVE-2026-50377: Windows Kernel Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50377</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50377</guid><description>Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50377) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Kernel Elevation of Privilege</category></item><item><title>CVE-2026-50407: Windows Resilient File System (ReFS) Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50407</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50407</guid><description>Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50407) was added to Microsoft’s security update guidance. Updated an ac</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Resilient File System (ReFS) Elevation of Privilege</category></item><item><title>CVE-2026-50441: Windows Resilient File System (ReFS) Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50441</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50441</guid><description>Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50441) was added to Microsoft’s security update guidance. Updated an ac</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Resilient File System (ReFS) Elevation of Privilege</category></item><item><title>CVE-2026-50458: Microsoft Brokering File System Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50458</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50458</guid><description>Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-50458) was added to Microsoft’s security update guidance. Updated an acknowl</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Brokering File System Elevation of Privilege</category></item><item><title>CVE-2026-50466: Microsoft Brokering File System Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50466</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50466</guid><description>Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-50466) was added to Microsoft’s security update guidance. Updated an acknowl</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Brokering File System Elevation of Privilege</category></item><item><title>CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50522</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50522</guid><description>Microsoft SharePoint is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-50522). Microsoft SharePoint contains a deserialization of untru</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>SharePoint</category><category>CISA KEV</category></item><item><title>CVE-2026-64188: rmnet_dellink() vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-64188</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-64188</guid><description>rmnet_dellink() vulnerability (CVE-2026-64188) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories </description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>rmnet_dellink</category><category>rmnet_dellink()</category></item><item><title>CVE-2026-64190: CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change</title><link>https://premierepc.com/security-briefs/cve-2026-64190</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-64190</guid><description>net net: team: fix NULL pointer dereference in team_xmit during mode change (CVE-2026-64190) was added to Microsoft’s security update guidance. Information</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>net</category><category>net: team: fix NULL pointer dereference in team_xmit during mode change</category></item><item><title>CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2021-27137</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2021-27137</guid><description>DD-WRT DD-WRT is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2021-27137). DD-WRT contains a stack-based buffer overflow vulnerability tha</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>DD-WRT</category><category>DD-WRT</category><category>CISA KEV</category></item><item><title>CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-0770</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-0770</guid><description>Langflow Langflow is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-0770). Langflow contains an inclusion of functionality from untrust</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>Langflow</category><category>CISA KEV</category></item><item><title>CVE-2026-38752: CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.</title><link>https://premierepc.com/security-briefs/cve-2026-38752</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-38752</guid><description>A A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a </description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>A</category><category>A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.</category></item><item><title>CVE-2026-38753: CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.</title><link>https://premierepc.com/security-briefs/cve-2026-38753</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-38753</guid><description>A A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>A</category><category>A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.</category></item><item><title>CVE-2026-38754: CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.</title><link>https://premierepc.com/security-briefs/cve-2026-38754</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-38754</guid><description>A A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>A</category><category>A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.</category></item><item><title>CVE-2026-38755: CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.</title><link>https://premierepc.com/security-briefs/cve-2026-38755</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-38755</guid><description>A A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafte</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>A</category><category>A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.</category></item><item><title>CVE-2026-50462: Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50462</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50462</guid><description>Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-50462) was added to Microsoft’s security update guidance. Upda</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Ancillary Function Driver for WinSock Elevation of Privilege</category></item><item><title>CVE-2026-58640: Windows NTFS Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-58640</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-58640</guid><description>Windows NTFS Remote Code Execution vulnerability (CVE-2026-58640) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows NTFS Remote Code Execution</category></item><item><title>CVE-2026-60137: WordPress Core SQL Injection Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-60137</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-60137</guid><description>WordPress Core is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-60137). WordPress Core contains a SQL injection vulnerability when a p</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>Core</category><category>CISA KEV</category></item><item><title>CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-63030</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63030</guid><description>WordPress Core is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-63030). WordPress Core contains an interpretation conflict vulnerabili</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>Core</category><category>CISA KEV</category></item><item><title>CVE-2026-63954: hpfs: fix a crash if hpfs_map_dnode_bitmap fails vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-63954</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63954</guid><description>hpfs: fix a crash if hpfs_map_dnode_bitmap fails vulnerability (CVE-2026-63954) was added to Microsoft’s security update guidance. Information published. P</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>hpfs</category><category>hpfs: fix a crash if hpfs_map_dnode_bitmap fails</category></item><item><title>CVE-2026-63978: CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit</title><link>https://premierepc.com/security-briefs/cve-2026-63978</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63978</guid><description>net net/handshake: Drain pending requests at net namespace exit (CVE-2026-63978) was added to Microsoft’s security update guidance. Information published. </description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>net</category><category>net/handshake: Drain pending requests at net namespace exit</category></item><item><title>CVE-2026-63979: CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doit</title><link>https://premierepc.com/security-briefs/cve-2026-63979</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63979</guid><description>net net/handshake: hand off the pinned file reference to accept_doit (CVE-2026-63979) was added to Microsoft’s security update guidance. Information publis</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>net</category><category>net/handshake: hand off the pinned file reference to accept_doit</category></item><item><title>CVE-2026-63983: CVE-2026-63983 net/sched: fix packet loop on netem when duplicate is on</title><link>https://premierepc.com/security-briefs/cve-2026-63983</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63983</guid><description>net net/sched: fix packet loop on netem when duplicate is on (CVE-2026-63983) was added to Microsoft’s security update guidance. Information published. Pre</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>net</category><category>net/sched: fix packet loop on netem when duplicate is on</category></item><item><title>CVE-2024-35248: Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2024-35248</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2024-35248</guid><description>Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-35248) was added to Microsoft’s security update guidance. Updated th</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Dynamics 365 Business Central Elevation of Privilege</category></item><item><title>CVE-2026-50304: Windows Active Directory Federation Services Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50304</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50304</guid><description>Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50304) was added to Microsoft’s security update guidance. Updated pr</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Active Directory Federation Services Denial of Service</category></item><item><title>CVE-2026-50324: Windows Active Directory Federation Services Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50324</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50324</guid><description>Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50324) was added to Microsoft’s security update guidance. Updated pr</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Active Directory Federation Services Denial of Service</category></item><item><title>CVE-2026-50355: Windows Active Directory Federation Services Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50355</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50355</guid><description>Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50355) was added to Microsoft’s security update guidance. Updated pr</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Active Directory Federation Services Denial of Service</category></item><item><title>CVE-2026-50368: Windows Active Directory Federation Services Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50368</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50368</guid><description>Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50368) was added to Microsoft’s security update guidance. Updated pr</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Active Directory Federation Services Denial of Service</category></item><item><title>CVE-2026-50411: Windows Active Directory Federation Services Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50411</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50411</guid><description>Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50411) was added to Microsoft’s security update guidance. Updated pr</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Active Directory Federation Services Denial of Service</category></item><item><title>CVE-2026-50652: Azure Active Directory Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50652</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50652</guid><description>Azure Active Directory Denial of Service vulnerability (CVE-2026-50652) was added to Microsoft’s security update guidance. Updated product information in t</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Active Directory Denial of Service</category></item><item><title>CVE-2026-50653: Azure Active Directory Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-50653</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-50653</guid><description>Azure Active Directory Denial of Service vulnerability (CVE-2026-50653) was added to Microsoft’s security update guidance. Updated product information in t</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Azure Active Directory Denial of Service</category></item><item><title>CVE-2026-63829: CVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink</title><link>https://premierepc.com/security-briefs/cve-2026-63829</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63829</guid><description>net net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829) was added to Microsoft’s security update guidance. Information p</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>net</category><category>net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink</category></item><item><title>CVE-2026-63830: CVE-2026-63830 net: skmsg: preserve sg.copy across SG transforms</title><link>https://premierepc.com/security-briefs/cve-2026-63830</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-63830</guid><description>net net: skmsg: preserve sg.copy across SG transforms (CVE-2026-63830) was added to Microsoft’s security update guidance. Information published. PremierePC</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>net</category><category>net: skmsg: preserve sg.copy across SG transforms</category></item><item><title>FBI Warns of Scammers Impersonating the IC3</title><link>https://premierepc.com/security-briefs/news-260720</link><guid isPermaLink="true">https://premierepc.com/security-briefs/news-260720</guid><description>FBI Warns of Scammers Impersonating the IC3 — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesse</description><pubDate>Mon, 20 Jul 2026 12:00:00 GMT</pubDate><category>FBI IC3</category><category>Industry news</category></item><item><title>CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-25089</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-25089</guid><description>Fortinet FortiSandbox is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-25089). Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSan</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category><category>CISA KEV</category></item><item><title>CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-39808</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-39808</guid><description>Fortinet FortiSandbox is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-39808). Fortinet FortiSandbox contains an OS command injection </description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category><category>CISA KEV</category></item><item><title>CVE-2026-56171: Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56171</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56171</guid><description>Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-56171) was added to Microsoft’s security update guidance. Exposure of </description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Remote Desktop Protocol (RDP) Information Disclosure</category></item><item><title>CVE-2026-58598: Windows Backup Service Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-58598</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-58598</guid><description>Windows Backup Service Elevation of Privilege vulnerability (CVE-2026-58598) was added to Microsoft’s security update guidance. Concurrent execution using </description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Backup Service Elevation of Privilege</category></item><item><title>CVE-2026-58643: Windows Admin Center Spoofing vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-58643</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-58643</guid><description>Windows Admin Center Spoofing vulnerability (CVE-2026-58643) was added to Microsoft’s security update guidance. Improper neutralization of input during web</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Admin Center Spoofing</category></item><item><title>CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2023-4346</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2023-4346</guid><description>KNX Association KNX Protocol Connection Authorization Option 1 is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2023-4346). KNX Association</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>KNX Association</category><category>KNX Protocol Connection Authorization Option 1</category><category>CISA KEV</category></item><item><title>CVE-2026-39822: os vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-39822</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-39822</guid><description>os vulnerability (CVE-2026-39822) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate S</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>os</category><category>os</category></item><item><title>CVE-2026-45637: Microsoft DWM Core Library Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-45637</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-45637</guid><description>Microsoft DWM Core Library Elevation of Privilege vulnerability (CVE-2026-45637) was added to Microsoft’s security update guidance. Updated acknowledgment.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft DWM Core Library Elevation of Privilege</category></item><item><title>CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-46817</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-46817</guid><description>Oracle E-Business Suite is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-46817). Oracle E-Business Suite contains an improper privileg</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>E-Business Suite</category><category>CISA KEV</category></item><item><title>CVE-2026-56182: Windows NTFS Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-56182</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-56182</guid><description>Windows NTFS Elevation of Privilege vulnerability (CVE-2026-56182) was added to Microsoft’s security update guidance. Updated acknowledgment. This is an in</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows NTFS Elevation of Privilege</category></item><item><title>CVE-2026-58644: Microsoft SharePoint Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-58644</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-58644</guid><description>Microsoft SharePoint Remote Code Execution vulnerability (CVE-2026-58644) was added to Microsoft’s security update guidance. Corrected the Exploitability I</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft SharePoint Remote Code Execution</category></item><item><title>CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-15409</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-15409</guid><description>SonicWall SMA1000 Appliances is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-15409). SonicWall SMA1000 Appliances contain a server-si</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>SMA1000 Appliances</category><category>CISA KEV</category></item><item><title>CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-15410</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-15410</guid><description>SonicWall SMA1000 Appliances is listed in CISA&apos;s Known Exploited Vulnerabilities catalog (CVE-2026-15410). SonicWall SMA1000 Appliances contain a code inje</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>SMA1000 Appliances</category><category>CISA KEV</category></item><item><title>CVE-2026-33842: Windows File Explorer Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-33842</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-33842</guid><description>Windows File Explorer Information Disclosure vulnerability (CVE-2026-33842) was added to Microsoft’s security update guidance. Exposure of sensitive inform</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows File Explorer Information Disclosure</category></item><item><title>CVE-2026-34328: Windows Audio Service Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-34328</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-34328</guid><description>Windows Audio Service Information Disclosure vulnerability (CVE-2026-34328) was added to Microsoft’s security update guidance. Exposure of sensitive inform</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Audio Service Information Disclosure</category></item><item><title>CVE-2026-34346: Windows Ancillary Function Driver for WinSock Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-34346</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-34346</guid><description>Windows Ancillary Function Driver for WinSock Information Disclosure vulnerability (CVE-2026-34346) was added to Microsoft’s security update guidance. Clea</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Ancillary Function Driver for WinSock Information Disclosure</category></item><item><title>CVE-2026-34348: Windows Event Logging Service Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-34348</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-34348</guid><description>Windows Event Logging Service Information Disclosure vulnerability (CVE-2026-34348) was added to Microsoft’s security update guidance. Protection mechanism</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Event Logging Service Information Disclosure</category></item><item><title>CVE-2026-34349: Windows Media Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-34349</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-34349</guid><description>Windows Media Information Disclosure vulnerability (CVE-2026-34349) was added to Microsoft’s security update guidance. Exposure of sensitive information to</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Media Information Disclosure</category></item><item><title>CVE-2026-40378: Windows Local Security Authority Subsystem Service (LSASS) Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-40378</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-40378</guid><description>Windows Local Security Authority Subsystem Service (LSASS) Denial of Service vulnerability (CVE-2026-40378) was added to Microsoft’s security update guidan</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Local Security Authority Subsystem Service (LSASS) Denial of Service</category></item><item><title>CVE-2026-40400: Windows PowerShell Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-40400</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-40400</guid><description>Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Relative path traversal in Windo</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows PowerShell Remote Code Execution</category></item><item><title>CVE-2026-40422: Windows File Explorer Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-40422</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-40422</guid><description>Windows File Explorer Information Disclosure vulnerability (CVE-2026-40422) was added to Microsoft’s security update guidance. Use of uninitialized resourc</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows File Explorer Information Disclosure</category></item><item><title>CVE-2026-41087: Windows File Explorer Information Disclosure vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-41087</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-41087</guid><description>Windows File Explorer Information Disclosure vulnerability (CVE-2026-41087) was added to Microsoft’s security update guidance. Exposure of sensitive inform</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows File Explorer Information Disclosure</category></item><item><title>CVE-2026-42897: Microsoft Exchange Server Spoofing vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-42897</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-42897</guid><description>Microsoft Exchange Server Spoofing vulnerability (CVE-2026-42897) was added to Microsoft’s security update guidance. Updated FAQ information. This is an in</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Exchange Server Spoofing</category></item><item><title>CVE-2026-42900: Microsoft Windows App Store Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-42900</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-42900</guid><description>Microsoft Windows App Store Elevation of Privilege vulnerability (CVE-2026-42900) was added to Microsoft’s security update guidance. Concurrent execution u</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Windows App Store Elevation of Privilege</category></item><item><title>CVE-2026-42975: Windows Bluetooth Port Driver Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-42975</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-42975</guid><description>Windows Bluetooth Port Driver Remote Code Execution vulnerability (CVE-2026-42975) was added to Microsoft’s security update guidance. Heap-based buffer ove</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Bluetooth Port Driver Remote Code Execution</category></item><item><title>CVE-2026-42982: Windows Secure Kernel Mode Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-42982</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-42982</guid><description>Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-42982) was added to Microsoft’s security update guidance. Improper validation of </description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Secure Kernel Mode Elevation of Privilege</category></item><item><title>CVE-2026-42990: SQL Server ODBC driver Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-42990</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-42990</guid><description>SQL Server ODBC driver Elevation of Privilege vulnerability (CVE-2026-42990) was added to Microsoft’s security update guidance. Heap-based buffer overflow </description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>SQL Server ODBC driver Elevation of Privilege</category></item><item><title>CVE-2026-44800: Windows Push Notifications Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-44800</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-44800</guid><description>Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-44800) was added to Microsoft’s security update guidance. Concurrent execution us</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Push Notifications Elevation of Privilege</category></item><item><title>CVE-2026-44806: Windows Secure Channel Denial of Service vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-44806</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-44806</guid><description>Windows Secure Channel Denial of Service vulnerability (CVE-2026-44806) was added to Microsoft’s security update guidance. Missing release of memory after </description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Windows Secure Channel Denial of Service</category></item><item><title>CVE-2026-45496: Visual Studio Code Security Feature Bypass vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-45496</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-45496</guid><description>Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-45496) was added to Microsoft’s security update guidance. Improper limitation of a pathn</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Visual Studio Code Security Feature Bypass</category></item><item><title>CVE-2026-47290: Microsoft Office Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-47290</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-47290</guid><description>Microsoft Office Remote Code Execution vulnerability (CVE-2026-47290) was added to Microsoft’s security update guidance. Use after free in Microsoft Office</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft Office Remote Code Execution</category></item><item><title>CVE-2026-47295: Microsoft SQL Server Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-47295</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-47295</guid><description>Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-47295) was added to Microsoft’s security update guidance. Improper neutralization of sp</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft SQL Server Elevation of Privilege</category></item><item><title>CVE-2026-47296: Microsoft SQL Server Elevation of Privilege vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-47296</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-47296</guid><description>Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-47296) was added to Microsoft’s security update guidance. Improper neutralization of sp</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Microsoft SQL Server Elevation of Privilege</category></item><item><title>CVE-2026-47305: Visual Studio Remote Code Execution vulnerability</title><link>https://premierepc.com/security-briefs/cve-2026-47305</link><guid isPermaLink="true">https://premierepc.com/security-briefs/cve-2026-47305</guid><description>Visual Studio Remote Code Execution vulnerability (CVE-2026-47305) was added to Microsoft’s security update guidance. Protection mechanism failure in Visua</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>Visual Studio Remote Code Execution</category></item></channel></rss>