CVE-2026-87886High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableLocal privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Sep 19, 2026
Disclosed via NVD
Last analysed / modified upstream
0.3%
Exploit / PoC code exists
Added to the CISA catalog on Sep 16, 2026. Federal remediation due Sep 19, 2026. View catalog ↗
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
acronis_backup < 1.2.3acronis_backup < 1.8.11acronis_backup < 1.9.3acronis_backup = 1.9.3Upgrade past the affected range:
acronis_backup 1.9.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1488High· 8.0A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration
CVE-2025-8766Medium· 6.4A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images
CVE-2026-52766Critical· 9.1YesWiki is a wiki system written in PHP
CVE-2026-92252Medium· 5.9Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Us…
CVE-2026-86359High· 8.5Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability
CVE-2026-86836High· 8.4In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration