CRITICAL 9 min read 16 Sep 2026

VMware vCenter CVE-2026-59310 now exploited by ransomware gangs Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-59310, cwe-22, cve-2026-61559, cve-2026-61568, cwe-918, cve-2023-36177, cwe-94, cve-2026-69205, cve-2026-69204, cve-2026-88975

Key findings
01
VMware vCenter CVE-2026-59310 now exploited by ransomware gangs
CRITICAL
CVE-2026-59310 is a critical vCenter Syslog Server directory-traversal flaw that permits unauthenticated arbitrary code execution. CISA newly marked the already-exploited flaw as used in ransomware campaigns; Broadcom released fixes in July.
02
Multiple vulnerabilities in @zereight/mcp-gitlab
CRITICAL
@zereight/mcp-gitlab carries 2 CVEs across 2 advisories: Vulnerable to Server-Side Request Forgery; DNS rebinding reaches local Streamable HTTP MCP transport. CVE coverage: CVE-2026-61559, CVE-2026-61568.
03
USN-8767-1: Snapcast vulnerability
CRITICAL
It was discovered that Snapcast incorrectly handled crafted JSON-RPC requests. A remote attacker could possibly use this issue to execute arbitrary code or obtain sensitive information. The assigned identifier is CVE-2023-36177.
04
Multiple vulnerabilities in Http4s Ember
CRITICAL
Http4s Ember carries 13 CVEs across 2 advisories: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS; Transfer-Encoding value parsing.
05
USN-8763-1: kitty vulnerabilities
HIGH
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. The assigned identifier is CVE-2026-42850.
06
USN-8770-1: SimpleSAMLphp vulnerabilities
HIGH
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. The assigned identifier is CVE-2019-3465.
07
USN-8769-1: phpseclib vulnerability
HIGH
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information. The assigned identifier is CVE-2026-32935.
08
kamailio: Uncontrolled Resource Consumption
HIGH
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree() The cited source identifies the affected product and the available advisory or remediation status.
09
Grafana: Authentication Bypass by Spoofing
HIGH
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key.
10
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
HIGH
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-61544.
11
Multiple vulnerabilities in Microsoft Edge
HIGH
CVE coverage: CVE-2026-69486, CVE-2026-85893. The cited advisories disclose: Remote Code Execution Vulnerability; Elevation of Privilege Vulnerability.
12
USN-8765-1: python-sql vulnerability
MEDIUM
Cédric Krier discovered that python-sql incorrectly escaped values passed to unary operators. An attacker could possibly use this issue to perform SQL injection attacks. The assigned identifier is CVE-2024-9774.
13
Portabilis i-Educar: SQL Injection
MEDIUM
A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. The assigned identifier is CVE-2025-9236.
14
Chromium CVE-2026-87439: Information leak in ServiceWorker
MEDIUM
The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-87439.
15
Acronis warns of actively exploited flaw in its cPanel backup plugin
INFO
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...].

Executive assessment

Today's brief leads with VMware vCenter CVE-2026-59310 now exploited by ransomware gangs. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Themes: Active exploitation of infrastructure products; MCP and HTTP request-handling flaws; PoC-driven exposure in network services. Patch order: Finding 01 (Critical vCenter issue exploited in the wild by ransomware gangs, with fixed versions available); Finding 03 (Critical Snapcast vulnerability with PoC exploitation and upstream plus Ubuntu fixes listed).

Finding 01 — VMware vCenter CVE-2026-59310 now exploited by ransomware gangs

What changed: CVE-2026-59310 is a critical vCenter Syslog Server directory-traversal flaw that permits unauthenticated arbitrary code execution. CISA newly marked the already-exploited flaw as used in ransomware campaigns; Broadcom released fixes in July.

Technical evidence: CVE-2026-59310; CVSS v3.1 9.8; weakness CWE-22; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: Restrict network access to vCenter management interfaces to authorised administrative systems only. Implement network segmentation to reduce exposure of management infrastructure. BleepingComputer reports that QUIRSO observed compromised systems connecting to attacker-controlled infrastructure from 3 August. ([kudelskisecurity.com](https://kudelskisecurity.com/research/vmware-security-advisory-cve-2026-59310), [bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/))

Affected: VMware Cloud Foundation 9.1.x.x, 9.0.x.x and 5.x; VMware vSphere Foundation 9.1.x.x and 9.0.x.x; VMware vCenter 9.1.x.x before 9.1.0.0300, 9.0.x.x before 9.0.2.0100 and 8.0 before 8.0 U3k; VMware Telc ([kudelskisecurity.com](https://kudelskisecurity.com/research/vmware-security-advisory-cve-2026-59310))

Fix: VMware vCenter 9.1.0.0300 or later, 9.0.2.0100 or later, and 8.0 U3k or later. ([kudelskisecurity.com](https://kudelskisecurity.com/research/vmware-security-advisory-cve-2026-59310))

Action: Map CVE-2026-59310 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/)

Finding 02 — Multiple vulnerabilities in @zereight/mcp-gitlab

What changed: @zereight/mcp-gitlab carries 2 CVEs across 2 advisories: Vulnerable to Server-Side Request Forgery; DNS rebinding reaches local Streamable HTTP MCP transport. CVE coverage: CVE-2026-61559, CVE-2026-61568.

Technical evidence: CVE-2026-61559; CVSS v3.1 9.6; weakness CWE-918; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Disable ENABLE_DYNAMIC_API_URL. If the feature is required, set GITLAB_ALLOWED_HOSTS to the exact trusted GitLab hostnames. ([github.com](https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj), [pluto.security](https://pluto.security/blog/two-critical-vulnerabilities-gitlab-mcp-account-takeover/), [intel.aikido.dev](https://intel.aikido.dev/cve/AIKIDO-2026-523251), +1 more)

Affected: Versions 0.0.1 through 2.1.26; Versions earlier than 2.1.30 ([intel.aikido.dev](https://intel.aikido.dev/cve/AIKIDO-2026-523251), [github.com](https://github.com/advisories/GHSA-vmp7-252j-cwp7))

Fix: Version 2.1.27; Version 2.1.30 ([intel.aikido.dev](https://intel.aikido.dev/cve/AIKIDO-2026-523251), [github.com](https://github.com/advisories/GHSA-vmp7-252j-cwp7))

Action: Map CVE-2026-61559 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-2h44-8472-frjj)

Finding 03 — USN-8767-1: Snapcast vulnerability

What changed: It was discovered that Snapcast incorrectly handled crafted JSON-RPC requests. A remote attacker could possibly use this issue to execute arbitrary code or obtain sensitive information.

Technical evidence: CVE-2023-36177; CVSS v3.1 9.8; weakness CWE-94; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Limit access to the Snapcast host; place it behind a reverse proxy with HTTP authentication or make it accessible only over a VPN. ([github.com](https://github.com/snapcast/snapcast/issues/860), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2023-36177), [ubuntu.com](https://ubuntu.com/security/notices/USN-8767-1))

Affected: Upstream Snapcast: the flaw was introduced in v0.16.0 and fixed in v0.30.0. ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2023-36177))

Fix: Upstream v0.30.0. Ubuntu snapclient and snapserver: 24.04 LTS 0.27.0+dfsg-1ubuntu0.1~esm1; 22.04 LTS 0.25.0+dfsg1-2ubuntu0.1~esm1; 20.04 LTS 0.18.1-1ubuntu0.1~esm1. ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2023-36177), [ubuntu.com](https://ubuntu.com/security/notices/USN-8767-1))

Action: Map CVE-2023-36177 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8767-1)

Finding 04 — Multiple vulnerabilities in Http4s Ember

What changed: Http4s Ember carries 13 CVEs across 2 advisories: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS; Transfer-Encoding value parsing. CVE coverage: CVE-2026-69205, CVE-2026-69204, CVE-2026-88975, CVE-2026-69201, CVE-2026-69218, CVE-2026-69216, CVE-2026-69215, CVE-2026-69214, CVE-2026-69213, CVE-2026-69208, CVE-2026-69206, CVE-2026-69203, CVE-2026-69202.

Technical evidence: CVE-2026-69205; CVSS v3.1 8.7; weakness CWE-444; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Until patched, configure the intermediary to reject requests containing both Transfer-Encoding and Content-Length, fully buffer and re-encode request bodies, and normalise Transfer-Encoding values before forwarding. Disable keep-alive between the intermediary and Ember. ([github.com](https://github.com/advisories/GHSA-8h4c-x2wg-6xp8), [github.com](https://github.com/advisories/GHSA-9998-894r-fwvr), [github.com](https://github.com/advisories/GHSA-gq9p-f254-h286), +1 more)

Affected: http4s versions earlier than 0.23.37 and 1.0.0 milestone versions earlier than 1.0.0-M48 ([github.com](https://github.com/advisories/GHSA-8h4c-x2wg-6xp8), [github.com](https://github.com/advisories/GHSA-9998-894r-fwvr), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-88975))

Fix: 0.23.35 and 1.0.0-M47; http4s 0.23.37 and 1.0.0-M48 ([github.com](https://github.com/advisories/GHSA-8h4c-x2wg-6xp8), [github.com](https://github.com/advisories/GHSA-9998-894r-fwvr), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-88975))

Action: Map CVE-2026-69205 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-9998-894r-fwvr)

Finding 05 — USN-8763-1: kitty vulnerabilities

What changed: It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands.

Technical evidence: CVE-2026-42850; CVSS v4.0 7.4; weakness CWE-77; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-42850 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8763-1)

Finding 06 — USN-8770-1: SimpleSAMLphp vulnerabilities

What changed: It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges.

Technical evidence: CVE-2019-3465; CVSS v3.1 8.8; weakness CWE-347; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2019-3465 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8770-1)

Finding 07 — USN-8769-1: phpseclib vulnerability

What changed: It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.

Technical evidence: CVE-2026-32935; CVSS v4.0 8.2; weakness CWE-208; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Disable AES-CBC and use AES in CTR, CFB or OFB mode until patching is possible. ([github.com](https://github.com/phpseclib/phpseclib/security/advisories/GHSA-94g3-g5v7-q4jg), [miggo.io](https://www.miggo.io/vulnerability-database/cve/CVE-2026-32935))

Fix: phpseclib 3.0.50, 2.0.52, and 1.0.27. ([github.com](https://github.com/phpseclib/phpseclib/security/advisories/GHSA-94g3-g5v7-q4jg))

Action: Map CVE-2026-32935 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8769-1)

Finding 08 — kamailio: Uncontrolled Resource Consumption

What changed: An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree() The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-52023.

Technical evidence: CVE-2026-52023; CVSS v3.1 7.5; weakness CWE-400; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-52023 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-52023)

Finding 09 — Grafana: Authentication Bypass by Spoofing

What changed: Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key.

Technical evidence: CVE-2026-14199; CVSS v3.1 7.1; weakness CWE-290, CWE-1023, CWE-863; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Set [auth.proxy] sync_ttl = 0 to disable the identity cache; identity is then synced on every request. ([access.redhat.com](https://access.redhat.com/security/cve/cve-2026-14199), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-14199), [grafana.com](https://grafana.com/security/security-advisories/cve-2026-14199/))

Affected: 11.0.0–11.6.17, 12.0.0–12.2.11, 12.3.0–12.3.11, 12.4.0–12.4.9, 13.0.0–13.0.7, 13.1.0–13.1.4, and 13.2.0. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-14199))

Action: Map CVE-2026-14199 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-14199)

Finding 10 — libp2p-quic: Remote panic via certificate expiry race during QUIC handshake

What changed: libp2p-quic: Remote panic via certificate expiry race during QUIC handshake The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-61544.

Technical evidence: CVE-2026-61544; CVSS v4.0 8.2; weakness CWE-248; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until patching, disable external access to the libp2p QUIC listener. Review application crash and panic logs around inbound QUIC connection handling. ([github.com](https://github.com/advisories/GHSA-5hq8-qhww-jm7q), [secalerts.co](https://secalerts.co/vulnerability/GHSA-5hq8-qhww-jm7q))

Affected: libp2p-quic versions earlier than 0.13.1. ([github.com](https://github.com/advisories/GHSA-5hq8-qhww-jm7q))

Fix: libp2p-quic 0.13.1. ([github.com](https://github.com/advisories/GHSA-5hq8-qhww-jm7q))

Action: Map CVE-2026-61544 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-5hq8-qhww-jm7q)

Finding 11 — Multiple vulnerabilities in Microsoft Edge

What changed: CVE coverage: CVE-2026-69486, CVE-2026-85893. The cited advisories disclose: Remote Code Execution Vulnerability; Elevation of Privilege Vulnerability.

Technical evidence: CVE-2026-69486; CVSS v3.1 8.8; weakness CWE-122; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until patching, block or quarantine untrusted Office files at email and web gateways. Restrict browsing to allow-listed sites for users running affected Edge versions to prevent visits to attacker-controlled webpages that can trigger autofill. Microsoft reports that neither CVE was publicly disclosed or exploited at original publication. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69486), [msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85893), [hkcert.org](https://www.hkcert.org/security-bulletin/microsoft-edge-multiple-vulnerabilities_20260916))

Affected: Microsoft Edge versions prior to 153.0.4234.32. ([hkcert.org](https://www.hkcert.org/security-bulletin/microsoft-edge-multiple-vulnerabilities_20260916))

Fix: Microsoft Edge 153.0.4234.32 or later. ([hkcert.org](https://www.hkcert.org/security-bulletin/microsoft-edge-multiple-vulnerabilities_20260916))

Action: Map CVE-2026-69486 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69486)

Finding 12 — USN-8765-1: python-sql vulnerability

What changed: Cédric Krier discovered that python-sql incorrectly escaped values passed to unary operators. An attacker could possibly use this issue to perform SQL injection attacks.

Technical evidence: CVE-2024-9774; CVSS v3.1 6.5; weakness CWE-150; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2024-9774 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8765-1)

Finding 13 — Portabilis i-Educar: SQL Injection

What changed: A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page.

Technical evidence: CVE-2025-9236; CVSS v4.0 5.3; weakness CWE-89, CWE-74; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-9236 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-9236)

Finding 14 — Chromium CVE-2026-87439: Information leak in ServiceWorker

What changed: The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-87439.

Technical evidence: CVE-2026-87439; CVSS v3.1 5.3; weakness CWE-200; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Affected: Google Chrome versions prior to 153.0.8010.36. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-87439))

Fix: Chrome 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and macOS. ([chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html))

Action: Map CVE-2026-87439 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026)

Finding 15 — Acronis warns of actively exploited flaw in its cPanel backup plugin

What changed: Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...].

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation reported by the source, not independently corroborated

fixed version or patch state unknown

[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/)

cve-2019-3465cve-2023-36177cve-2024-9774cve-2025-9236cve-2026-14199cve-2026-32935cve-2026-42850cve-2026-52023cve-2026-59310cve-2026-61544

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.