Skip to main content

CVE tracking · CISA known exploited

Security Briefs — vulnerability alerts in plain English

Tracked flaws from CISA’s exploited-vulnerability catalog, Microsoft security advisories, and other U.S. feeds — Windows, firewalls, VPN appliances, Microsoft 365, firmware, and network gear. Each alert explains what’s affected, how serious it is, and whether attackers are already using it.

Alerts tracked

1642

Published security flaws we monitor for Upstate SC businesses.

Known exploited

489

On CISA’s list of vulnerabilities attackers are actively using — patch these first.

New exploited this month

28

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 11, 2026, 6:00 AM UTC.

What do these terms mean?
  • What is a CVE?

    A CVE (Common Vulnerabilities and Exposures) is a public tracking number for a specific security flaw in software or hardware, similar to a SKU for a bug.

  • What is the CISA Known Exploited Vulnerabilities (KEV) catalog?

    The CISA KEV catalog is the U.S. government’s short list of vulnerabilities that attackers are actively exploiting in the wild — not just theoretical risks.

  • Who publishes Security Briefs on PremierePC?

    PremierePC tracks alerts from CISA KEV, Microsoft MSRC, FBI IC3 industry advisories, and other U.S. feeds, then summarizes impact in plain English for Upstate SC businesses.

  • How often are Security Briefs updated?

    Feeds sync automatically on a schedule. New KEV entries, Microsoft advisories, and federal industry alerts are published as they appear in source catalogs.

Showing 4 of 4 alerts.

Actively exploited (KEV)Ransomware

CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8088). RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. CISA remediation due date: 2025-09-02. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

RARLAB·WinRAR

Actively exploited (KEV)Ransomware

CVE-2025-42999

SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-42999). SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. CISA remediation due date: 2025-06-05. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

SAP·NetWeaver

Actively exploited (KEV)Ransomware

CVE-2024-23692

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23692). Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. CISA remediation due date: 2024-07-30. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2021-40438

Apache HTTP Server-Side Request Forgery (SSRF) vulnerability

Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Apache·Apache