ZeroHour

Vulnerabilities

1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87886
Incorrect Default Permissions in Acronis Backup Plugin for cPanel & WHM and Plesk Enable Privilege Escalation

CVE-2026-87886 is an incorrect default permissions flaw (CWE-276) in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Because files or objects installed by the plugin/extension carry overly permissive default permissions, a local attacker with low-privileged access to a Linux hosting server can abuse them to escalate privileges. Successful exploitation grants elevated Linux privileges on the hosting server, which could enable persistence, access to hosted customer data, or further lateral movement. Any hosting provider or administrator running the Acronis Backup integration on cPanel & WHM or Plesk servers is affected. The flaw was added to the CISA KEV catalog on 2026-09-16, and multiple reports describe targeted attacks exploiting it in the wild, though no public proof-of-concept is known and ransomware use is undetermined.

Do: Upgrade the Acronis Backup plugin for cPanel & WHM and the Plesk extension to the latest versions specified in Acronis's security advisory, since fixed version numbers are not provided in the available data. Audit affected Linux hosting servers for signs of local privilege escalation (unexpected setuid/permission changes, new privileged accounts, unusual cron or service activity), and restrict low-privileged shell access to the server where possible. As the flaw is on CISA's KEV list, federal and BOD 26-04-bound stakeholders must apply vendor mitigations on internet-exposed and high-risk assets on an accelerated timeline.

KEV
  • Acronis Backup plugin for cPanel & WHM
  • Acronis Backup extension for Plesk
moderatelikely thousands to tens of thousands of cPanel/WHM and Plesk hosting servers with the Acronis Backup integration installed