Skip to main content

CVE tracking · CISA known exploited

Security Briefs — vulnerability alerts in plain English

Tracked flaws from CISA’s exploited-vulnerability catalog, Microsoft security advisories, and other U.S. feeds — Windows, firewalls, VPN appliances, Microsoft 365, firmware, and network gear. Each alert explains what’s affected, how serious it is, and whether attackers are already using it.

Alerts tracked

1642

Published security flaws we monitor for Upstate SC businesses.

Known exploited

489

On CISA’s list of vulnerabilities attackers are actively using — patch these first.

New exploited this month

28

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 11, 2026, 6:00 AM UTC.

What do these terms mean?
  • What is a CVE?

    A CVE (Common Vulnerabilities and Exposures) is a public tracking number for a specific security flaw in software or hardware, similar to a SKU for a bug.

  • What is the CISA Known Exploited Vulnerabilities (KEV) catalog?

    The CISA KEV catalog is the U.S. government’s short list of vulnerabilities that attackers are actively exploiting in the wild — not just theoretical risks.

  • Who publishes Security Briefs on PremierePC?

    PremierePC tracks alerts from CISA KEV, Microsoft MSRC, FBI IC3 industry advisories, and other U.S. feeds, then summarizes impact in plain English for Upstate SC businesses.

  • How often are Security Briefs updated?

    Feeds sync automatically on a schedule. New KEV entries, Microsoft advisories, and federal industry alerts are published as they appear in source catalogs.

Showing 24 of 1145 alerts from the selected feed.

HighMicrosoft MSRC

CVE-2021-34474

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability (CVE-2021-34474) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2021-36946

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-36946) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2021-40440

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-40440) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability (CVE-2024-21380) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2024-38225

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-38225) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2025-29821

Microsoft Dynamics Business Central Information Disclosure vulnerability

Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2025-29821) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-40417

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2026-40417) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50309

Windows NTFS Remote Code Execution vulnerability

Windows NTFS Remote Code Execution vulnerability (CVE-2026-50309) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50357

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50357) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2025-49506

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability (CVE-2025-49506) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-40400

Windows PowerShell Remote Code Execution vulnerability

Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50481

Azure Active Directory Elevation of Privilege vulnerability

Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50515

Azure Service Bus Remote Code Execution vulnerability

Azure Service Bus Remote Code Execution vulnerability (CVE-2026-50515) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50516

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-50516) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-55050

Microsoft Word Information Disclosure vulnerability

Microsoft Word Information Disclosure vulnerability (CVE-2026-55050) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56161

Azure Logic Apps Information Disclosure vulnerability

Azure Logic Apps Information Disclosure vulnerability (CVE-2026-56161) was added to Microsoft’s security update guidance. Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56162

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-56162) was added to Microsoft’s security update guidance. Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-59115

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability (CVE-2026-59115) was added to Microsoft’s security update guidance. '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-59118

Microsoft Power Apps Elevation of Privilege vulnerability

Microsoft Power Apps Elevation of Privilege vulnerability (CVE-2026-59118) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-62830

Azure SRE Agent Elevation of Privilege vulnerability

Azure SRE Agent Elevation of Privilege vulnerability (CVE-2026-62830) was added to Microsoft’s security update guidance. Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-62836

Azure SQL Managed Instance Elevation of Privilege vulnerability

Azure SQL Managed Instance Elevation of Privilege vulnerability (CVE-2026-62836) was added to Microsoft’s security update guidance. Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-62869

Azure Entra ID Spoofing vulnerability

Azure Entra ID Spoofing vulnerability (CVE-2026-62869) was added to Microsoft’s security update guidance. Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-62873

Microsoft 365 Admin Center Elevation of Privilege vulnerability

Microsoft 365 Admin Center Elevation of Privilege vulnerability (CVE-2026-62873) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-62896

Microsoft Teams Elevation of Privilege vulnerability

Microsoft Teams Elevation of Privilege vulnerability (CVE-2026-62896) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.