LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CVE-2026-87886high

Acronis Backup Flaw Exploited Before CVE Publication

The Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) was reported as exploited two days before its official CVE publication date, leaving no patch window for affected organizations.

zeroday.news ·

A vulnerability in Acronis Backup, identified as CVE-2026-87886, was exploited in the wild at least two days before its public disclosure. The flaw, described as an incorrect default permissions vulnerability, affects the Acronis Backup plugin for cPanel & WHM and the extension for Plesk, and could lead to privilege escalation.

The vulnerability was first listed in a Known Exploited Vulnerabilities (KEV) catalog on September 15, 2026, while the CVE was officially published on September 17, 2026. Both the U.S. federal CISA KEV and the European Union's ENISA EUVD listed the vulnerability as exploited on September 16, 2026. A commercial research KEV from VulnCheck also reported exploitation on September 15, 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87886 to its KEV catalog on September 16, 2026, with a federal fix deadline of September 19, 2026. CISA advises organizations to apply mitigations in accordance with vendor instructions and to evaluate the internet exposure of affected assets. If mitigations are unavailable, CISA recommends discontinuing use of the product.

Acronis confirmed the exploitation and released a security advisory, SEC-10986, which was publicly available by September 15, 2026. The vulnerability has a "high" severity rating, though a specific CVSS score was not provided in the available information. The Exploit Prediction Scoring System (EPSS) for this CVE is 0.25%, placing it in the 17.4th percentile, suggesting a relatively low probability of exploitation despite confirmed in-the-wild activity.

vulnerabilities in this storyCVE-2026-87886
vulnerabilityzero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details

vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

CVE-2026-9055critical

WordPress Amelia Plugin Flaw Exploited Before CVE Publication

A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.

CVE-2026-46331high

Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEV

A Linux kernel vulnerability, CVE-2026-46331, has been confirmed as exploited, but remains absent from the US federal CISA Known Exploited Vulnerabilities (KEV) catalogue.

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]