Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Acronis urgently patched CVE-2026-87886 (CVSS 7.8), insecure file permissions enabling privilege escalation, exploited in targeted attacks on cPanel & WHM backups.
Acronis released urgent patches for CVE-2026-87886 (CVSS 7.8), insecure file permissions in the Backup plugin for cPanel & WHM and the Backup extension for Plesk that allow attackers to gain elevated privileges. Exploitation has been detected in the wild in limited, targeted attacks against the cPanel & WHM plugin, but not against the Plesk extension. All Linux versions of the plugin before build 1.9.3.1021 and the Plesk extension before build 1.8.11.638 are affected; Acronis urges immediate updates and has not shared technical details.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel patched critical flaw CVE-2026-65643 letting authenticated hosting customers with addon or parked domain rights execute code as root and fully compromise servers.
cPanel issued patches on August 27, 2026 for CVE-2026-65643, a flaw in domain parking and addon domain functionality in cPanel & WHM that lets an authenticated account holder create arbitrary files and execute code as root, yielding full server control. Fixed builds cover the 11.110, 11.134, 11.136 and 11.138 branches, including WP Squared 11.138.1.7, and auto-update servers receive the fix automatically. No CVSS score, published CVE record, or evidence of exploitation has appeared, and the flaw is absent from CISA's KEV catalog as of August 27. The article also recaps related 2026 cPanel-ecosystem issues, including KEV-listed LiteSpeed plugin flaws and the in-the-wild-exploited Phusion Passenger problem.
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Weekly recap: actively exploited Chrome V8 zero-day, MikroTik RouterOS zero-day chain, Magento StyleSmuggler backdoor, and critical N-able N-central flaws.
Google patched an actively exploited Chrome V8 type confusion zero-day, CVE-2026-85046 (CVSS 8.8), the sixth exploited Chrome zero-day of 2026. CERT Polska warned of the MikroTrick exploit chain (CVE-2026-67276 and CVE-2026-86060, CVSS 9.2) giving unauthenticated full control of MikroTik RouterOS devices via SSH, observed since September 2. Sansec disclosed the StyleSmuggler Magento/Adobe Commerce zero-day used since September 4 to inject a Rust backdoor into online stores, while N-able patched three critical N-central flaws (CVE-2026-86206, CVE-2026-86207, and CVE-2026-86218, CVSS 10.0) with Huntress observing likely exploitation. Elastic and Morphisec also detailed RevStealer, an information stealer spread via game cheats and a fake Claude Desktop app.