CVE-2026-87886: Acronis Cyber Protect Backup Local Privilege Escalation Added to CISA KEV Catalog

Technical teardown of CVE-2026-87886 in Acronis Cyber Protect: backup agent privilege escalation, shadow copy tampering, and CISA KEV remediation.

CVE-2026-87886: Acronis Cyber Protect Backup Local Privilege Escalation Added to CISA KEV Catalog
📌
Security Roundup Series: Week of September 18, 2026 • 5 min read deep dive

A local privilege escalation vulnerability in Acronis Cyber Protect Backup Agent (CVE-2026-87886) has been cataloged in CISA KEV following in-the-wild exploitation by ransomware operators to hijack backup repositories and wipe shadow copies.

🛡️
Vulnerability Intelligence: CVE ID: CVE-2026-87886 (CWE-269: Improper Privilege Management in Backup Agent Service) Severity: High (CVSS 7.8) Status: 🚨 Added to CISA KEV Catalog / Active Ransomware Targeting Affected Systems: Acronis Cyber Protect Windows Agent versions prior to update C24.08

Ransomware Pre-Encryption Tactics

Threat actors deploy low-privilege malware that exploits unquoted service paths and permissive IPC handles in the Acronis backup daemon. By elevating to SYSTEM, the adversary deletes immutable backup snapshots before launching full-scale volume encryption.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther