Skip to main content

CVE tracking · CISA known exploited

Security Briefs: vulnerability alerts in plain English

We track CISA KEV, Microsoft advisories, and FBI alerts, then tell you what’s affected and whether attackers are already using it.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 5, 2026, 6:01 AM UTC.

What do these terms mean?
  • What is a CVE?

    A CVE (Common Vulnerabilities and Exposures) is a public tracking number for a specific security flaw in software or hardware, similar to a SKU for a bug.

  • What is the CISA Known Exploited Vulnerabilities (KEV) catalog?

    The CISA KEV catalog is the U.S. government’s short list of vulnerabilities that attackers are actively exploiting in the wild.

  • Who publishes Security Briefs on PremierePC?

    PremierePC tracks alerts from CISA KEV, Microsoft MSRC, FBI IC3 industry advisories, and other U.S. feeds, then summarizes what each one means for Upstate SC businesses.

  • How often are Security Briefs updated?

    Feeds sync automatically on a schedule. We publish new KEV entries, Microsoft advisories, and FBI alerts as they appear in the source catalogs.

Showing 24 of 3384 alerts from the selected feed.

HighMicrosoft MSRC

CVE-2025-10502

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2025-10502) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-96940

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-96940) was added to Microsoft’s security update guidance. Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49800

Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege vulnerability

Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege vulnerability (CVE-2026-49800) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50414

Windows Media Elevation of Privilege vulnerability

Windows Media Elevation of Privilege vulnerability (CVE-2026-50414) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50400

Windows App Package Installer Elevation of Privilege vulnerability

Windows App Package Installer Elevation of Privilege vulnerability (CVE-2026-50400) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50357

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50357) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50332

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50332) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-4450

Out of bounds write in V8 in Microsoft Edge vulnerability

Out of bounds write in V8 in Microsoft Edge vulnerability (CVE-2026-4450) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-100208

Microsoft Office Outlook Remote Code Execution vulnerability

Microsoft Office Outlook Remote Code Execution vulnerability (CVE-2026-100208) was added to Microsoft’s security update guidance. Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not ne… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-100206

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-100206) was added to Microsoft’s security update guidance. Information published. This CVE was addressed by updates that were released in July 2026, but the CVE was inadvertently omitted from the July 2026 Security Updates. This is an informational change only. Customers who have already installed the July 2026 updates do not need to… If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2025-2135

Type Confusion in V8 in Microsoft Edge vulnerability

Type Confusion in V8 in Microsoft Edge vulnerability (CVE-2025-2135) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54981

Visual Studio Code Python Extension Security Feature Bypass vulnerability

Visual Studio Code Python Extension Security Feature Bypass vulnerability (CVE-2026-54981) was added to Microsoft’s security update guidance. Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.… If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-70125

Microsoft Outlook Remote Code Execution vulnerability

Microsoft Outlook Remote Code Execution vulnerability (CVE-2026-70125) was added to Microsoft’s security update guidance. Information published. This CVE was addressed by updates that were released in September 2026, but the CVE was inadvertently omitted from the September 2026 Security Updates. This is an informational change only. Customers who have already installed the September 2026 updates… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57091

Windows File History Service Elevation of Privilege vulnerability

Windows File History Service Elevation of Privilege vulnerability (CVE-2026-57091) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55134

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-55134) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55123

Microsoft PowerPoint Remote Code Execution vulnerability

Microsoft PowerPoint Remote Code Execution vulnerability (CVE-2026-55123) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55039

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55039) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40400

Windows PowerShell Remote Code Execution vulnerability

Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-88097

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-0899

Out of bounds memory access in V8 in Microsoft Edge vulnerability

Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-87701

Azure Cosmos DB Elevation of Privilege vulnerability

Azure Cosmos DB Elevation of Privilege vulnerability (CVE-2026-87701) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85917

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85917) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85889

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85889) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85885

Microsoft 365 Copilot Elevation of Privilege vulnerability

Microsoft 365 Copilot Elevation of Privilege vulnerability (CVE-2026-85885) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.