Daily briefing · September 17, 2026
Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitation
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
September 17, 2026 delivers a dense vulnerability landscape: six Microsoft Azure services received CVSS 10.0 privilege-escalation patches in a single release cycle, while CVE-2026-87886 in Acronis Backup extension for Plesk was already observed being exploited in the wild by VulnCheck before any official CISA confirmation — a critical early-warning signal. With 1,051 new CVEs published and 72 rated critical, defenders face a broad attack surface requiring immediate triage, particularly across cloud and backup infrastructure.
Today’s brief
- Acronis Backup plugin (cPanel, Plesk, DirectAdmin) under active exploitation — patch to latest builds immediately
- Six Azure services (Fabric, Billing, AI Foundry, Logic Apps x2, Arc, Container Registry) each carry a perfect CVSS 10.0 privilege-escalation flaw
- vm2 sandbox escape and prebid-server-java SSRF round out the critical list with serious server-side risks
- Brazil is heavily targeted by ransomware: four new victims disclosed recently across hospitality, accounting, transport and other sectors
Critical highlights
1
CVE-2026-87886◆ VulnCheckHIGH 7.8affects Acronis Backup extension for Plesk A local privilege escalation via insecure file permissions in Acronis Backup plugins for cPanel, Plesk, and DirectAdmin on Linux — already observed exploited in the wild by VulnCheck before CISA confirmation, making patching to build 1.9.3.1021 / 1.8.11.638 / 1.2.3.238 respectively an emergency priority for hosting and MSP environments.
2
Authentication bypass by spoofing in Microsoft Fabric (CVSS 10.0) allows an unauthenticated network attacker to elevate privileges, putting entire enterprise analytics and data-lakehouse workloads at risk of full takeover.
3
Insufficient verification of data authenticity in Azure Billing enables an unauthorized attacker to elevate privileges over the network — a particularly sensitive target given billing-plane access can expose financial data and subscription-level controls.
4
Missing authentication for a critical function in Azure AI Foundry (CVSS 10.0) permits unauthenticated privilege escalation over the network, threatening AI pipeline integrity and any data processed through Foundry workspaces.
5
A path traversal flaw in Azure Logic Apps allows an unauthenticated attacker to elevate privileges remotely; given Logic Apps often serve as integration hubs between cloud and on-premises systems, a successful exploit could pivot across connected services.
6
Improper access control in Azure Logic Apps (a second critical flaw, CVSS 10.0) compounds the risk for Logic Apps deployments, offering yet another unauthenticated privilege-escalation path that organizations must address alongside CVE-2026-70200.
7
Azure Arc elevation of privilege (CVSS 10.0) is particularly dangerous because Arc is designed to bridge on-premises and multi-cloud environments — a successful escalation here could grant attackers lateral movement across hybrid infrastructure.
8
Authorization bypass through a user-controlled key in Microsoft Container Registry allows unauthenticated privilege escalation, threatening the integrity of container image pipelines and supply-chain security for organizations relying on Azure-hosted registries.
9
Prebid Server Java before 3.43.0 allows SSRF via unsanitized bidder adapter parameters, enabling attackers to redirect the server to internal network destinations — a serious risk in ad-tech stacks where prebid instances may have broad internal network access.
10
vm2 before 3.11.6 leaks access to os and dns Node.js builtins under wildcard configuration, allowing sandbox escapes and global DNS hijacking via dns.setServers() — any application using vm2 as a security boundary must treat this as a sandbox bypass with immediate host-level impact.
Ransomware today
Several Brazilian organizations have been claimed as ransomware victims in recent days, with thegentlemen and qilin among the most aggressive groups. Newly disclosed victims include fchhotels.com (Hospitality, claimed by settra), Multipla Contabilidade Empresarial (Professional Services, thegentlemen), Humboldt (thegentlemen), and Alicotrans (Transportation, qilin). Over the past 30 days, thegentlemen leads activity with nine confirmed victims — all in Brazil — underscoring a concentrated targeting campaign against Brazilian organizations.
fchhotels.com BRsettra · Hospitality
Multipla Contabilidade Empresarial BRthegentlemen · Professional Services
Humboldt BRthegentlemen · Other
Alicotrans BRqilin · Transportation
thegentlemen 9krybit 3Vexy Ransomware 2settra 2emperador 2kazu 2
Active groups & APTs
Several threat actor groups are currently tracked as active: mosesstaff (Iran-linked), siegedsec (Russia-linked), sinobi, spacebears, thegentlemen, and funksec. While no specific victim counts are currently attributed to individual actors beyond ransomware disclosures, the presence of Iranian and Russian-nexus groups alongside financially motivated operators signals a multi-vector threat environment requiring both patching and threat-hunting discipline.
Brazil focus
Brazil continues to face intense ransomware pressure across multiple sectors. Recent victims reported over the past 30 days include fchhotels.com (Hospitality), Humboldt, Multipla Contabilidade Empresarial (Professional Services), Alicotrans (Transportation), Tuboaços da Amazônia Ltda. (Manufacturing), Logar Network Solutions (Technology), amorsaude.com.br (Healthcare, LockBit 5), and Alurwalls (Manufacturing, Dark Project) — demonstrating that no sector is being spared and that groups such as thegentlemen are running sustained campaigns specifically targeting Brazilian entities.
fchhotels.comsettra · Hospitality
Humboldtthegentlemen · Other
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Alicotransqilin · Transportation
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
AlurwallsDark Project · Manufacturing
Today’s recommendation: Prioritize immediate patching of Acronis Backup plugins on all Linux hosting panels given confirmed in-the-wild exploitation, and treat all six Azure CVSS 10.0 flaws as critical cloud-hygiene items — verify whether your Azure tenants are exposed and apply Microsoft's mitigations or service-side patches as soon as they are available. Additionally, audit any vm2 and prebid-server-java deployments and update to the fixed versions to close sandbox-escape and SSRF vectors.
Understanding which of today's critical flaws intersect with your actual infrastructure requires continuous visibility into your own attack surface — now is the moment to validate your exposure before adversaries do it for you.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →