Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Acronis urgently patched CVE-2026-87886 (CVSS 7.8), insecure file permissions enabling privilege escalation, exploited in targeted attacks on cPanel & WHM backups.
Acronis released urgent patches for CVE-2026-87886 (CVSS 7.8), insecure file permissions in the Backup plugin for cPanel & WHM and the Backup extension for Plesk that allow attackers to gain elevated privileges. Exploitation has been detected in the wild in limited, targeted attacks against the cPanel & WHM plugin, but not against the Plesk extension. All Linux versions of the plugin before build 1.9.3.1021 and the Plesk extension before build 1.8.11.638 are affected; Acronis urges immediate updates and has not shared technical details.
- CVE-2026-87886 (CVSS 7.8): insecure file permissions allow privilege escalation in Acronis Backup tooling
- Exploitation observed in limited, targeted attacks against cPanel & WHM plugin deployments only
- Affected: Linux plugin builds before 1.9.3.1021 and Plesk extension builds before 1.8.11.638
- Acronis withholds technical details and urges users to update deployments immediately
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87886 | NVD description · AI analysis pending | — | — | — | — | — |
Full article316 words · extracted from securityweek.com · click to collapse
Acronis on Tuesday rolled out urgent patches for a vulnerability in the Backup plugin for cPanel & WHM that has been exploited in the wild.
The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments.
Insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges.
The vulnerability is tracked as CVE-2026-87886 (CVSS score of 7.8) and has been exploited in the wild against the plugin, but not against the extension.
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory.
The company says all Linux versions of the Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638 are affected.
Advertisement. Scroll to continue reading.
Acronis has not shared technical details on the vulnerability but urges users to update their deployments immediately.
Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Related: Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Ionut Arghire is an international correspondent for SecurityWeek.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/acronis-patches-exploited-vulnerability-in-cpanel-backup-plugin/