Acronis Backup Plugin Flaw Exploited
Acronis has disclosed CVE-2026-87886, a high-severity Linux privilege-escalation flaw in its cPanel and Plesk backup plugins, citing limited in-the-wild attacks.
30 results for “exploit”
Acronis has disclosed CVE-2026-87886, a high-severity Linux privilege-escalation flaw in its cPanel and Plesk backup plugins, citing limited in-the-wild attacks.
Cisco warns CVE-2026-76461, a CVSS 9.8 flaw in Secure Email Gateway, is being exploited to run commands as root, with a federal patch deadline of September 17.
A new draft code of conduct would block its MAI models from generating working exploit code while opening a review track for defensive security work.
Sysdig says a hand-built toolkit let a human operator exploit a Marimo flaw in eight seconds, without any sign of LLM use.
Dutch NCSC warns two critical Check Point VPN flaws could be exploited soon, after fixes shipped on September 9.
GitLab patches a maximum-severity path traversal flaw and a critical EE deserialization bug as researchers report in-the-wild probing within hours.
Wiz reports attackers chained two Artifactory token flaws to seize admin control and plant backdoors, while a third flaw was exploited separately.
A new exploit kit chains four Chrome and Windows flaws, revealing how quickly attackers weaponize the delay between open-source fixes and stable browser patches.
Nightmare Eclipse drops ShieldCrash, a fresh Microsoft Defender zero-day that bypasses incomplete fixes for the ShieldBreak exploit.
Cisco says attackers are exploiting a maximum-severity Secure FMC bug, but its own July advisory points to earlier activity.
Proofpoint says China-aligned clusters rapidly adopted BlueMoon, a Chrome and Windows exploit chain that may have cost far less to build than expected.
Proofpoint says an exploit kit chaining two Chromium flaws and a Windows bug hit four suspected China-linked espionage groups within days.
Tencent patches zero-click flaw that allowed account takeover via VoIP calls.
Google patches an in-the-wild V8 out-of-bounds write bug, marking the seventh exploited zero-day this year.
Microsoft's September release tops 964 fixes, including two exploited zero-days and a wormable DNS flaw.
Microsoft fixes 974 flaws, including two exploited zero-days, but only a few matter to most orgs.
Sansec reports active attacks on a max-severity Magento flaw, with backdoors and secondary access found.
N-able shipped a fourth N-central hotfix for a critical RCE flaw, but its own statements conflict on whether it's been exploited.
CERT Poland warns of active exploitation of two critical MikroTik RouterOS vulnerabilities, enabling full router hijacking.
Attackers exploit exposed SSH on MikroTik routers for full admin access; CERT Polska urges patching.
Attackers are actively exploiting a critical file upload bug in the popular Elementor Pro WordPress plugin.
Attackers exploit two PaperCut flaws to steal credentials from schools and universities in the U.S. and Europe.
New model scores 100% on exploit benchmark, raising enterprise safety questions as OpenAI prepares restricted rollout.
Google patches a high-severity type confusion bug in V8 that has been exploited in the wild, the sixth zero-day fixed this year.
The researcher known as Nightmare Eclipse has released FalconFlank, a privilege escalation exploit targeting CrowdStrike Falcon via a Windows Office macro feature.
Citizen Lab finds NSO Group spyware on an activist's iPhone via a zero-click exploit, highlighting ongoing surveillance of Serbian civil society.
CVE-2026-9586, an unauthenticated SQL injection in Switchvox, is under active exploitation, Horizon3 reports.
Rockwell Automation ships fixes for 13+ flaws, including critical RSLinx DoS and an exploited-tagged issue.
Forescout researchers used AI to port RCE exploits to PLCs, but high cost and effort still deter criminals.
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.