{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/acunetix-25.11.251107123/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:acunetix:acunetix:25.11.251107123:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-6958"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Acunetix (25.11.251107123)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","local-exploitation"],"_cs_type":"advisory","_cs_vendors":["Acunetix"],"content_html":"\u003cp\u003eAcunetix 25.11.251107123 for Windows contains a critical local privilege escalation (LPE) vulnerability in its Web Vulnerability Scanning Engine (wvsc.exe). The issue stems from the application expecting certain OpenSSL-related files to exist in a specific path that is not hardcoded or properly restricted. A low-privileged local user can proactively create the missing directory structure and inject a malicious DLL file into the expected location. When the wvsc.exe process, which executes with SYSTEM privileges, attempts to load these dependencies, it loads the attacker-controlled file instead. This results in arbitrary code execution with SYSTEM-level permissions. This vulnerability, identified as CVE-2026-6958, allows any local attacker to elevate their privileges to full administrative control over the host system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a low-privileged local user to escalate their permissions to the SYSTEM level on a system running the affected version of Acunetix. This can lead to total system compromise, including the installation of persistent backdoors, data exfiltration, and lateral movement within the network. The vulnerability impacts organizations using Acunetix 25.11.251107123 on Windows platforms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately: Upgrade Acunetix installations to a version that addresses CVE-2026-6958.\u003c/li\u003e\n\u003cli\u003eImplement monitoring: Monitor for file creation events in directories where high-privilege applications search for library dependencies.\u003c/li\u003e\n\u003cli\u003eRestrict permissions: Ensure that standard user accounts do not have write access to system directories or application installation folders where such hijacking can occur.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T15:27:17Z","date_published":"2026-09-04T15:27:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-acunetix-lpe/","summary":"Acunetix 25.11.251107123 for Windows is vulnerable to local privilege escalation via DLL hijacking in the Web Vulnerability Scanning Engine (wvsc.exe) due to insecure directory path handling.","title":"Local Privilege Escalation in Acunetix Web Vulnerability Scanning Engine","url":"https://feed.craftedsignal.io/briefs/2026-09-acunetix-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - Acunetix (25.11.251107123)","version":"https://jsonfeed.org/version/1.1"}