Vulnerabilities
Vulnerable Software
Security Vulnerabilities
CVE-2026-87886
Known exploited
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-17
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-09-17
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.0
EPSS Score
0.004
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.006
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-09-17
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-17
Azure Arc Elevation of Privilege Vulnerability
CVSS Score
10.0
EPSS Score
0.005
Published
2026-09-17
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
CVSS Score
8.6
EPSS Score
0.005
Published
2026-09-17
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
6.1
EPSS Score
0.004
Published
2026-09-17
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application linked to OpenImageIO can reach BMP palette handling in src/bmp.imageio/bmpinput.cpp with an empty color table. BmpInput::read_native_scanline then performs an invalid palette read while decoding an RLE-compressed scanline, causing a process crash and denial of service. This issue is fixed in versions 3.0.16.0 and 3.1.11.0.
CVSS Score
5.5
EPSS Score
0.002
Published
2026-09-17


Contact Us

Shodan ® - All rights reserved