ScreenConnect, Issabel PBX, and Acronis Flaws Under Active Attack

by The Creator | Sep 16, 2026

Four critical vulnerabilities are actively exploited right now: ScreenConnect remote access (CVE-2026-89026), Issabel PBX phone systems (CVE-2026-87886), Acronis backup software, and WooCommerce plugin backdoors. Your breach response plan must include immediate patching, staff phishing training, and tested backups, since the average attack costs SMBs $52,000 in downtime and recovery.

CISA warns that attackers are actively exploiting a critical vulnerability in ConnectWise ScreenConnect remote support software. Businesses using ScreenConnect should update immediately, as this tool provides broad network access that attackers can exploit. A critical security flaw (severity 9.3/10, CVE-2026-89026) in Issabel PBX phone systems is being actively exploited, allowing attackers to execute commands remotely without authentication. Organizations using Issabel for VoIP should apply security patches urgently. Acronis has confirmed targeted attacks exploiting a high-severity vulnerability (CVE-2026-87886, CVSS 7.8) in its Backup plugin for cPanel, which allows privilege escalation. Web hosting providers and cPanel administrators should update immediately.

Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells to WordPress sites, creating hidden backdoors. WordPress site owners should check and update all WooCommerce plugins, particularly wholesale and lead-capture extensions. A new phishing kit called GhostCode bypasses Microsoft 365 multi-factor authentication in approximately 78 seconds by tricking users into approving what appears to be a legitimate login request. The attacks begin with convincing messages through business contact forms, impersonating buyers or vendors. Employee training is the primary defense, as real login requests will never originate from cold contacts.

New research from Hiscox reveals that cyber attacks now cost businesses an average of $52,000, including downtime, recovery costs, lost business, and legal expenses. For small businesses, this represents a significant survival threat. The study shows that organizations with pre-established incident response plans, tested backups, and cyber insurance recover fastest. Many costs are operational, including staff time and lost deals, beyond just ransom payments or forensics.

What should your breach response plan include this week?

CISA is warning of active exploitation of ScreenConnect (used by many MSPs and IT support teams), Issabel PBX systems, and Acronis backup plugins. The GhostCode phishing kit bypasses Microsoft 365 MFA in 78 seconds by impersonating vendors or buyers via contact forms, then tricks employees into approving fake login requests. For SMBs, the threat window is immediate. Your breach response plan should prioritize: (1) patch ScreenConnect and Acronis today if you use them, (2) block suspicious login approval requests through employee training, (3) audit WooCommerce plugins for backdoors, and (4) confirm backups are offline and tested. Hiscox data shows organizations with pre-established response plans and cyber insurance recover fastest and spend less on unplanned downtime.

Key takeaways

  • Patch ScreenConnect, Issabel PBX, and Acronis backup plugins now; these flaws are actively exploited.
  • GhostCode phishing kit bypasses MFA by impersonating vendors through cold contact messages; train staff to reject unexpected login approvals.
  • Average breach costs SMBs $52,000 in downtime, recovery, and lost business; a written response plan cuts recovery time significantly.
  • Verify backups are isolated from the network and tested quarterly; ransomware exploits backup access as a second target.

Frequently asked questions

Do we use ScreenConnect? How do I know if we're at risk?

ScreenConnect is remote support software used by IT service providers and some businesses for employee support access. Check your installed software list or ask your IT team. CISA CVE-2026-89026 affects all versions; update immediately through ConnectWise.

What does GhostCode phishing actually do?

GhostCode tricks employees into approving a fake Microsoft 365 login request by posing as a vendor or buyer through a business contact form. The attacker monitors the approval screen and gains account access in under 80 seconds. Real login requests never come from cold contacts.

How much does a breach actually cost a small business?

Hiscox reports the average is $52,000, including downtime (lost revenue), staff time on recovery, legal obligations, and forensics. For manufacturing or professional services firms, even 24 hours offline can exceed this cost. Insurance and pre-tested backups reduce both recovery time and total expense.

What's the first step in breach response?

Isolate affected systems from the network immediately (don't shut them down), activate your backup, notify your IT team or MSP, and document the timeline. If ransomware is suspected, preserve evidence and contact law enforcement through IC3.gov. Do not pay any demand without counsel.

Sources

Keep reading