Skip to main content

CVE tracking · CISA known exploited

Security Briefs: vulnerability alerts in plain English

We track CISA KEV, Microsoft advisories, and FBI alerts, then tell you what’s affected and whether attackers are already using it.

Alerts tracked

2625

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.

What do these terms mean?
  • What is a CVE?

    A CVE (Common Vulnerabilities and Exposures) is a public tracking number for a specific security flaw in software or hardware, similar to a SKU for a bug.

  • What is the CISA Known Exploited Vulnerabilities (KEV) catalog?

    The CISA KEV catalog is the U.S. government’s short list of vulnerabilities that attackers are actively exploiting in the wild.

  • Who publishes Security Briefs on PremierePC?

    PremierePC tracks alerts from CISA KEV, Microsoft MSRC, FBI IC3 industry advisories, and other U.S. feeds, then summarizes what each one means for Upstate SC businesses.

  • How often are Security Briefs updated?

    Feeds sync automatically on a schedule. We publish new KEV entries, Microsoft advisories, and FBI alerts as they appear in the source catalogs.

Showing 24 of 2114 alerts from the selected feed.

Microsoft MSRC

CVE-2026-70338

Microsoft PowerShell Security Feature Bypass vulnerability

Microsoft PowerShell Security Feature Bypass vulnerability (CVE-2026-70338) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66804

Microsoft Windows Cross Device Service Elevation of Privilege vulnerability

Microsoft Windows Cross Device Service Elevation of Privilege vulnerability (CVE-2026-66804) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65791

Windows iSCSI Target Service Remote Code Execution vulnerability

Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65791) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56642

Microsoft Fabric Data Warehouse Remote Code Execution vulnerability

Microsoft Fabric Data Warehouse Remote Code Execution vulnerability (CVE-2026-56642) was added to Microsoft’s security update guidance. Updated the Security Updates table by removing an affected software entry. No user action is required. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50419

Windows Kernel Information Disclosure vulnerability

Windows Kernel Information Disclosure vulnerability (CVE-2026-50419) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47632

Azure Connected Machine Agent Elevation of Privilege vulnerability

Azure Connected Machine Agent Elevation of Privilege vulnerability (CVE-2026-47632) was added to Microsoft’s security update guidance. Corrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-24301

Microsoft Copilot Information Disclosure vulnerability

Microsoft Copilot Information Disclosure vulnerability (CVE-2026-24301) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70337

Microsoft PowerShell Remote Code Execution vulnerability

Microsoft PowerShell Remote Code Execution vulnerability (CVE-2026-70337) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66807

Microsoft Office Graphics Component Remote Code Execution vulnerability

Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-66807) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63519

Microsoft Office Graphics Component Remote Code Execution vulnerability

Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-63519) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63518

Microsoft Office Word Remote Code Execution vulnerability

Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-63518) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63513

Microsoft Office Graphics Component Remote Code Execution vulnerability

Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-63513) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56188

Windows Server Network driver Remote Code Execution vulnerability

Windows Server Network driver Remote Code Execution vulnerability (CVE-2026-56188) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40400

Windows PowerShell Remote Code Execution vulnerability

Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65769

Microsoft Teams iOS Information Disclosure vulnerability

Microsoft Teams iOS Information Disclosure vulnerability (CVE-2026-65769) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65768

Microsoft Teams Remote Code Execution vulnerability

Microsoft Teams Remote Code Execution vulnerability (CVE-2026-65768) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65767

Microsoft Teams for Android Spoofing vulnerability

Microsoft Teams for Android Spoofing vulnerability (CVE-2026-65767) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59124

Microsoft High Performance Computing (HPC) Pack Remote Code Execution vulnerability

Microsoft High Performance Computing (HPC) Pack Remote Code Execution vulnerability (CVE-2026-59124) was added to Microsoft’s security update guidance. Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72970

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-72970) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69414

Microsoft Defender Elevation of Privilege vulnerability

Microsoft Defender Elevation of Privilege vulnerability (CVE-2026-69414) was added to Microsoft’s security update guidance. Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68821

Windows Package Manager Elevation of Privilege vulnerability

Windows Package Manager Elevation of Privilege vulnerability (CVE-2026-68821) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62777

Windows License Manager Elevation of Privilege vulnerability

Windows License Manager Elevation of Privilege vulnerability (CVE-2026-62777) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62755

Windows DHCP Client Elevation of Privilege vulnerability

Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-62755) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61347

Windows Event Logging Service Information Disclosure vulnerability

Windows Event Logging Service Information Disclosure vulnerability (CVE-2026-61347) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.