Acronis Patches Exploited Linux Privilege Escalation Flaw (CVE-2026-87886) in cPanel/Plesk Backup Plugins; CISA Adds It to KEV Catalog
Acronis urgently patched CVE-2026-87886 (CVSS 7.8), an insecure file permissions flaw enabling local privilege escalation on Linux in its Backup plugin for cPanel & WHM and Backup extension for Plesk; exploitation was observed in limited, targeted attacks…
Acronis disclosed and patched CVE-2026-87886 (CVSS 7.8, CWE-276), a local privilege escalation vulnerability caused by insecure file permissions in its Backup plugin for cPanel & WHM and Backup extension for Plesk on Linux. A low-privileged local attacker with a prior foothold could escalate permissions and potentially run arbitrary code, affecting the confidentiality and integrity of the application; Security Affairs characterizes the impact as local root-level code execution, while other reports describe it as privilege escalation with potential arbitrary code execution. Affected products are cPanel & WHM plugin builds before 1.9.3.1021 (fixed in version 1.9.3 HF3) and Plesk extension builds before 1.8.11.638; Acronis urges immediate updates. Exploitation has been detected in the wild in limited, targeted attacks against cPanel & WHM deployments only, with no exploitation observed against the Plesk extension. Acronis has not identified the attackers, timing, or objectives, and has withheld technical details. On September 17, 2026, Security Affairs reported that CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog alongside CVE-2026-76460 (CVSS 10.0, unauthenticated API authentication bypass in Cisco ISE, confirmed actively exploited) and CVE-2026-58704 (CVSS 8.8, Google Pixel cellular modem permission bypass patched in the September 2026 Pixel update); under BOD 22-01, U.S. federal agencies must remediate KEV entries by the stated due dates, and private organizations are urged to review the catalog. GBHackers notes that because exploitation requires a prior foothold, shared hosting and multi-tenant environments are especially concerning.
- CVE-2026-87886 (CVSS 7.8, CWE-276): insecure file permissions allow a low-privileged local attacker to escalate privileges on Linux servers.
- Affected: cPanel & WHM Backup plugin Linux builds before 1.9.3.1021 (fixed in 1.9.3 HF3) and Plesk Backup extension builds before 1.8.11.638 (fixed in 1.8.11).
- Exploitation confirmed in limited, targeted attacks against cPanel & WHM deployments only; no exploitation observed against the Plesk extension.
- Acronis has not identified the attackers, timing, or objectives, and has withheld technical details.
- Sources disagree on impact severity: The Hacker News reports privilege escalation with potential arbitrary code execution affecting confidentiality and integrity; Security Affairs describes local root-level code execution.
Coverage timelineoldest first · each row is one article
- · 11d agoAcronis Patches Exploited Vulnerability in cPanel Backup Plugin
SecurityWeek· 72
Acronis urgently patched CVE-2026-87886 (CVSS 7.8), insecure file permissions enabling privilege escalation, exploited in targeted attacks on cPanel & WHM backups.
- · 11d agoAcronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges
GBHackers· 62
Acronis patched CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in its cPanel & WHM backup plugin already exploited in targeted attacks.
Vulnerabilities in this storyAll →
- CVE-2026-587048.8<1%Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalationpublished · Google Cellular Modem (modem firmware on Google Pixel-class devices, per assigning CNA) KEV
- CVE-2026-7646010.0