Daily briefing · September 17, 2026

Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitation

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

September 17, 2026 delivers a dense vulnerability landscape: six Microsoft Azure services received CVSS 10.0 privilege-escalation patches in a single release cycle, while CVE-2026-87886 in Acronis Backup extension for Plesk was already observed being exploited in the wild by VulnCheck before any official CISA confirmation — a critical early-warning signal. With 1,051 new CVEs published and 72 rated critical, defenders face a broad attack surface requiring immediate triage, particularly across cloud and backup infrastructure.

Today’s brief
  • Acronis Backup plugin (cPanel, Plesk, DirectAdmin) under active exploitation — patch to latest builds immediately
  • Six Azure services (Fabric, Billing, AI Foundry, Logic Apps x2, Arc, Container Registry) each carry a perfect CVSS 10.0 privilege-escalation flaw
  • vm2 sandbox escape and prebid-server-java SSRF round out the critical list with serious server-side risks
  • Brazil is heavily targeted by ransomware: four new victims disclosed recently across hospitality, accounting, transport and other sectors
72
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-87886◆ VulnCheckHIGH 7.8affects Acronis Backup extension for Plesk
A local privilege escalation via insecure file permissions in Acronis Backup plugins for cPanel, Plesk, and DirectAdmin on Linux — already observed exploited in the wild by VulnCheck before CISA confirmation, making patching to build 1.9.3.1021 / 1.8.11.638 / 1.2.3.238 respectively an emergency priority for hosting and MSP environments.
2
CVE-2026-69843CVSS 10affects Microsoft Fabric
Authentication bypass by spoofing in Microsoft Fabric (CVSS 10.0) allows an unauthenticated network attacker to elevate privileges, putting entire enterprise analytics and data-lakehouse workloads at risk of full takeover.
3
CVE-2026-62874CVSS 10affects Azure Billing
Insufficient verification of data authenticity in Azure Billing enables an unauthorized attacker to elevate privileges over the network — a particularly sensitive target given billing-plane access can expose financial data and subscription-level controls.
4
CVE-2026-85889CVSS 10affects Azure AI Foundry
Missing authentication for a critical function in Azure AI Foundry (CVSS 10.0) permits unauthenticated privilege escalation over the network, threatening AI pipeline integrity and any data processed through Foundry workspaces.
5
CVE-2026-70200CVSS 10affects Azure Logic Apps
A path traversal flaw in Azure Logic Apps allows an unauthenticated attacker to elevate privileges remotely; given Logic Apps often serve as integration hubs between cloud and on-premises systems, a successful exploit could pivot across connected services.
6
CVE-2026-83944CVSS 10affects Azure Logic Apps
Improper access control in Azure Logic Apps (a second critical flaw, CVSS 10.0) compounds the risk for Logic Apps deployments, offering yet another unauthenticated privilege-escalation path that organizations must address alongside CVE-2026-70200.
7
CVE-2026-69399CVSS 10affects Azure ARC
Azure Arc elevation of privilege (CVSS 10.0) is particularly dangerous because Arc is designed to bridge on-premises and multi-cloud environments — a successful escalation here could grant attackers lateral movement across hybrid infrastructure.
8
CVE-2026-69865CVSS 10affects Azure Container Registry
Authorization bypass through a user-controlled key in Microsoft Container Registry allows unauthenticated privilege escalation, threatening the integrity of container image pipelines and supply-chain security for organizations relying on Azure-hosted registries.
9
CVE-2026-54734CVSS 10affects prebid-server-java
Prebid Server Java before 3.43.0 allows SSRF via unsanitized bidder adapter parameters, enabling attackers to redirect the server to internal network destinations — a serious risk in ad-tech stacks where prebid instances may have broad internal network access.
10
CVE-2026-92960CVSS 10affects vm2
vm2 before 3.11.6 leaks access to os and dns Node.js builtins under wildcard configuration, allowing sandbox escapes and global DNS hijacking via dns.setServers() — any application using vm2 as a security boundary must treat this as a sandbox bypass with immediate host-level impact.
Ransomware today

Several Brazilian organizations have been claimed as ransomware victims in recent days, with thegentlemen and qilin among the most aggressive groups. Newly disclosed victims include fchhotels.com (Hospitality, claimed by settra), Multipla Contabilidade Empresarial (Professional Services, thegentlemen), Humboldt (thegentlemen), and Alicotrans (Transportation, qilin). Over the past 30 days, thegentlemen leads activity with nine confirmed victims — all in Brazil — underscoring a concentrated targeting campaign against Brazilian organizations.

fchhotels.com BRsettra · Hospitality
Multipla Contabilidade Empresarial BRthegentlemen · Professional Services
Humboldt BRthegentlemen · Other
Alicotrans BRqilin · Transportation
thegentlemen 9krybit 3Vexy Ransomware 2settra 2emperador 2kazu 2
Active groups & APTs

Several threat actor groups are currently tracked as active: mosesstaff (Iran-linked), siegedsec (Russia-linked), sinobi, spacebears, thegentlemen, and funksec. While no specific victim counts are currently attributed to individual actors beyond ransomware disclosures, the presence of Iranian and Russian-nexus groups alongside financially motivated operators signals a multi-vector threat environment requiring both patching and threat-hunting discipline.

Brazil focus

Brazil continues to face intense ransomware pressure across multiple sectors. Recent victims reported over the past 30 days include fchhotels.com (Hospitality), Humboldt, Multipla Contabilidade Empresarial (Professional Services), Alicotrans (Transportation), Tuboaços da Amazônia Ltda. (Manufacturing), Logar Network Solutions (Technology), amorsaude.com.br (Healthcare, LockBit 5), and Alurwalls (Manufacturing, Dark Project) — demonstrating that no sector is being spared and that groups such as thegentlemen are running sustained campaigns specifically targeting Brazilian entities.

fchhotels.comsettra · Hospitality
Humboldtthegentlemen · Other
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Alicotransqilin · Transportation
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
AlurwallsDark Project · Manufacturing
Today’s recommendation: Prioritize immediate patching of Acronis Backup plugins on all Linux hosting panels given confirmed in-the-wild exploitation, and treat all six Azure CVSS 10.0 flaws as critical cloud-hygiene items — verify whether your Azure tenants are exposed and apply Microsoft's mitigations or service-side patches as soon as they are available. Additionally, audit any vm2 and prebid-server-java deployments and update to the fixed versions to close sandbox-escape and SSRF vectors.
Understanding which of today's critical flaws intersect with your actual infrastructure requires continuous visibility into your own attack surface — now is the moment to validate your exposure before adversaries do it for you.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share