ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)
Part of a story covered by 6 sources: “Acronis patches actively exploited CVE-2026-87886 privilege escalation flaw in cPanel/WHM and Plesk backup plugins” — merged summary and timeline →

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

highExploit / PoC exploited in the wildimportance 65CVE-2026-87886
AI summary · glm-5.3-flash

Acronis warns CVE-2026-87886, a local privilege escalation flaw in its cPanel/WHM and Plesk backup plugins, is exploited in targeted attacks.

Acronis disclosed CVE-2026-87886 (CVSS 7.8), a high-severity local privilege escalation caused by insecure file permissions in its Backup plugin for cPanel & WHM and Backup extension for Plesk on Linux. Affected versions include cPanel & WHM plugin builds before 1.9.3.1021 (fixed in 1.9.3 HF3) and Plesk extension builds before 1.8.11.638. A low-privileged attacker could escalate permissions and potentially run arbitrary code, impacting confidentiality and integrity of the application. Acronis says exploitation has been detected in the wild in limited, targeted attacks, but has not identified the attackers, timing, or objectives.

  • CVE-2026-87886 (CVSS 7.8) is a local privilege escalation caused by insecure file permissions
  • Affects cPanel & WHM plugin before build 1.9.3.1021 and Plesk extension before build 1.8.11.638
  • Exploitation observed in limited, targeted attacks; actor and motive unknown
  • Fixed in 1.9.3 HF3; users urged to install updates immediately

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87886

NVD description · AI analysis pending
Full article273 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 16, 2026Vulnerability / Linux

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.

The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions -

Successful exploitation of the flaw could allow an attacker with low privileges to escalate their permissions on a susceptible Linux version, potentially enabling them to perform unauthorized actions or run arbitrary code that could impact the confidentiality and integrity of the application.

"This update contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users," Acronis noted in a separate advisory for 1.9.3 HF3. "Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks."

There are currently no details about the vulnerability, or who is behind the attacks exploiting it and what the end goals are. It's also not clear when the activity was detected and since when the security flaw may have been exploited in the wild.

The Hacker News has contacted Acronis for comment and we will update the story if we hear back. Customers of the Acronis backup plugin are advised to apply the latest updates as soon as possible to stay protected.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html