CVE tracking · CISA known exploited
Security Briefs: vulnerability alerts in plain English
We track CISA KEV, Microsoft advisories, and FBI alerts, then tell you what’s affected and whether attackers are already using it.
Alerts tracked
3893
Security flaws we track for Upstate SC businesses.
Known exploited
528
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
12
Fresh additions to that CISA list since the first of the month.Feeds last synced Sep 13, 2026, 6:01 AM UTC.
What do these terms mean?
What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a public tracking number for a specific security flaw in software or hardware, similar to a SKU for a bug.
What is the CISA Known Exploited Vulnerabilities (KEV) catalog?
The CISA KEV catalog is the U.S. government’s short list of vulnerabilities that attackers are actively exploiting in the wild.
Who publishes Security Briefs on PremierePC?
PremierePC tracks alerts from CISA KEV, Microsoft MSRC, FBI IC3 industry advisories, and other U.S. feeds, then summarizes what each one means for Upstate SC businesses.
How often are Security Briefs updated?
Feeds sync automatically on a schedule. We publish new KEV entries, Microsoft advisories, and FBI alerts as they appear in the source catalogs.
Showing 24 of 360 alerts from the selected feed.
Broadcom VMware vCenter Path Traversal Vulnerability
Broadcom VMware vCenter is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-59310). Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. CISA remediation due date: 2026-08-21. If you need help checking exposure, call (864) 335-9223.
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20316). Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. CISA remediation due date: 2026-08-01. If you need help checking exposure, call (864) 335-9223.
SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall SMA1000 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-15410). SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CISA remediation due date: 2026-07-17. If you need help checking exposure, call (864) 335-9223.
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-15409). SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. CISA remediation due date: 2026-07-17. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45659). Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. CISA remediation due date: 2026-07-04. If you need help checking exposure, call (864) 335-9223.
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
PTC Windchill and FlexPLM is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-12569). PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. CISA remediation due date: 2026-06-28. If you need help checking exposure, call (864) 335-9223.
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-35273). Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. CISA remediation due date: 2026-06-15. If you need help checking exposure, call (864) 335-9223.
Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-50751). Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. CISA remediation due date: 2026-06-11. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0257). Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. CISA remediation due date: 2026-06-01. If you need help checking exposure, call (864) 335-9223.
Nx Console Embedded Malicious Code Vulnerability
Nx Nx Console is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48027). Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. CISA remediation due date: 2026-06-10. If you need help checking exposure, call (864) 335-9223.
TanStack Unspecified Vulnerability
TanStack TanStack is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45321). TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. CISA remediation due date: 2026-06-10. If you need help checking exposure, call (864) 335-9223.
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WebPros cPanel & WHM and WP2 (WordPress Squared) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-41940). WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. CISA remediation due date: 2026-05-03. If you need help checking exposure, call (864) 335-9223.
ConnectWise ScreenConnect Path Traversal Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1708). ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. CISA remediation due date: 2026-05-12. If you need help checking exposure, call (864) 335-9223.
SimpleHelp Path Traversal Vulnerability
SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57728). SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.
SimpleHelp Missing Authorization Vulnerability
SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57726). SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. CISA remediation due date: 2026-05-08. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-33825). Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. CISA remediation due date: 2026-05-06. If you need help checking exposure, call (864) 335-9223.
JetBrains TeamCity Relative Path Traversal Vulnerability
JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-27199). JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. CISA remediation due date: 2026-05-04. If you need help checking exposure, call (864) 335-9223.
PaperCut NG/MF Improper Authentication Vulnerability
PaperCut NG/MF is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27351). PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. CISA remediation due date: 2026-05-04. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Link Following Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-60710). Microsoft Windows contains a link following vulnerability that allows for privilege escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-21529). Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.
Secure Firewall Management Center (FMC) vulnerability
Cisco Secure Firewall Management Center (FMC) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20131). Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. CISA remediation due date: 2026-03-22. If you need help checking exposure, call (864) 335-9223.
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds Web Help Desk is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-26399). SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. CISA remediation due date: 2026-03-12. If you need help checking exposure, call (864) 335-9223.
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-1731). BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption. CISA remediation due date: 2026-02-16. If you need help checking exposure, call (864) 335-9223.
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
SmarterTools SmarterMail is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-24423). SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. CISA remediation due date: 2026-02-26. If you need help checking exposure, call (864) 335-9223.