30
30
57
60
55
30
55
60
57
60
30
57
30
57
57
60
60
60
30
55
30
30
30
60
55
Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wildnew
Acronis patched CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in its cPanel and Plesk backup plugins, exploited in targeted attacks.
Acronis released fixes for CVE-2026-87886 (CVSS 7.8, CWE-276), an insecure file permissions flaw in Linux-based backup components for cPanel & WHM and Plesk that enables local privilege escalation. The vendor observed limited, targeted exploitation in the wild before patches shipped. Fixes are available in Backup plugin for cPanel & WHM 1.9.3 HF3 and Backup extension for Plesk 1.8.11. A local attacker with low privileges could gain elevated access to backup data, control panels, and other customer accounts on shared hosting infrastructure.
65
45
30
30
30
60
60
60
30
30
30
30
42
60
55