CISA adds actively exploited Acronis cPanel/Plesk backup plugin flaw CVE-2026-87886 to KEV catalog
CISA has added CVE-2026-87886 (CVSS 7.8, CWE-276) to its Known Exploited Vulnerabilities catalog, days after Acronis patched the insecure file permissions flaw that lets a low-privileged local attacker escalate privileges on Linux via its Backup plugin for…
Acronis has disclosed and patched CVE-2026-87886 (CVSS 7.8, CWE-276), an insecure file permissions vulnerability that allows a low-privileged, authenticated local attacker to escalate privileges on Linux servers running the Acronis Backup plugin for cPanel & WHM or the Acronis Backup extension for Plesk. All Linux builds of the cPanel & WHM plugin before 1.9.3.1021 and all Plesk extension builds before 1.8.11.638 are affected. The low-complexity attack requires no user interaction but does require a prior local foothold; successful exploitation can grant access to or modification of backup data, control panels, and other customer accounts on shared hosting infrastructure, and The Hacker News notes it could potentially allow arbitrary code execution impacting confidentiality and integrity, while Security Affairs describes root-level code execution. Acronis detected exploitation in the wild in limited, targeted attacks before patches shipped — BleepingComputer reports this determination is based on a single customer report — and exploitation has been confirmed only against cPanel & WHM deployments, with none observed on Plesk. Acronis has not identified the attackers, timing, or objectives; no indicators of compromise have been published, and technical details are being withheld to allow time for patching. Fixes shipped the week before public disclosure: Backup plugin for cPanel & WHM 1.9.3 HF3 (build 1.9.3.1021 or later) and Backup extension for Plesk 1.8.11 (build 1.8.11.638 or later). On 2026-09-17, Security Affairs reported that CISA has added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog, alongside Cisco ISE CVE-2026-76460 (CVSS 10.0, unauthenticated API authentication bypass) and Google Pixel CVE-2026-58704 (CVSS 8.8, cellular modem permission bypass); under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates, and private organizations are urged to review the catalog. Hosting providers and MSPs are urged to prioritize patching due to multi-tenant risk; defenders are advised to review authentication logs, web-shell detections, and Acronis file modifications.
- CVE-2026-87886 (CVSS 7.8, CWE-276) is an insecure file permissions flaw enabling low-privileged, authenticated local privilege escalation on Linux; the low-complexity attack requires no user interaction but does require a prior local…
- Affected: all Linux builds of the Acronis Backup plugin for cPanel & WHM before 1.9.3.1021 and all builds of the Acronis Backup extension for Plesk before 1.8.11.638.
- Fixed in Backup plugin for cPanel & WHM 1.9.3 HF3 (build 1.9.3.1021 or later) and Backup extension for Plesk 1.8.11 (build 1.8.11.638 or later); patches shipped the week before public disclosure.
- Exploitation detected in the wild in limited, targeted attacks against cPanel & WHM deployments only; no exploitation observed on Plesk; BleepingComputer reports Acronis's determination is based on a single customer report.
- Acronis has not identified the attackers, timing, or objectives; no indicators of compromise have been published and technical details are withheld to allow time for patching.
- Potential impact includes access to or modification of backup data, control panels, and other customer accounts on shared hosting; The Hacker News notes potential arbitrary code execution impacting confidentiality and integrity, and…
- CISA has added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog (reported 2026-09-17), alongside Cisco ISE CVE-2026-76460 (CVSS 10.0) and Google Pixel CVE-2026-58704 (CVSS 8.8); under BOD 22-01, federal agencies must remediate…
- Defenders advised: hosting providers and MSPs should prioritize patching due to multi-tenant risk; review authentication logs, web-shell detections, and Acronis file modifications.
Coverage timelineoldest first · each row is one article
- · 1d agoAcronis warns of actively exploited flaw in its cPanel backup plugin
BleepingComputer· 65
Acronis reports CVE-2026-87886, a CVSS 7.8 Linux privilege escalation in its cPanel/WHM and Plesk backup plugins, exploited in limited targeted attacks.
- · 1d agoAcronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild
Cyber Security News· 65
Acronis patched CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in its cPanel and Plesk backup plugins, exploited in targeted attacks.
- · 1d agoAcronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
Help Net Security· 72
Acronis warns CVE-2026-87886, an authenticated Linux privilege escalation flaw in its cPanel, WHM, and Plesk backup plugins, is under limited targeted exploitation; patches released.
- · 1d agoAcronis Patches Exploited Vulnerability in cPanel Backup Plugin
SecurityWeek· 72
Acronis urgently patched CVE-2026-87886 (CVSS 7.8), insecure file permissions enabling privilege escalation, exploited in targeted attacks on cPanel & WHM backups.
- · 1d agoAcronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges
GBHackers· 62
Acronis patched CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in its cPanel & WHM backup plugin already exploited in targeted attacks.
- · 1d agoAcronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
The Hacker News· 65
Acronis warns CVE-2026-87886, a local privilege escalation flaw in its cPanel/WHM and Plesk backup plugins, is exploited in targeted attacks.
- · 4h agoU.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Security Affairs· 80
CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58704 | Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA ([email protected]), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments. Do: Install the latest Google monthly security update that includes the cellular modem firmware patch and verify the device's security patch level reflects it. Because exploitation requires network adjacency plus some existing privilege, prioritize devices used in high-risk or shared-network settings and watch for indicators of rogue femtocell/base-station or hostile local-network activity. With no public PoC or KEV listing, standard monthly patch cadence is reasonable outside those high-risk scenarios. | 8.8 | <1% | KEV |
| masstens of millions of devices (≈10M+ active Pixel-class handsets worldwide) | |
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces | |
| CVE-2026-87886 | Incorrect Default Permissions in Acronis Backup Plugin for cPanel & WHM and Plesk Enable Privilege Escalation CVE-2026-87886 is an incorrect default permissions flaw (CWE-276) in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Because files or objects installed by the plugin/extension carry overly permissive default permissions, a local attacker with low-privileged access to a Linux hosting server can abuse them to escalate privileges. Successful exploitation grants elevated Linux privileges on the hosting server, which could enable persistence, access to hosted customer data, or further lateral movement. Any hosting provider or administrator running the Acronis Backup integration on cPanel & WHM or Plesk servers is affected. The flaw was added to the CISA KEV catalog on 2026-09-16, and multiple reports describe targeted attacks exploiting it in the wild, though no public proof-of-concept is known and ransomware use is undetermined. Do: Upgrade the Acronis Backup plugin for cPanel & WHM and the Plesk extension to the latest versions specified in Acronis's security advisory, since fixed version numbers are not provided in the available data. Audit affected Linux hosting servers for signs of local privilege escalation (unexpected setuid/permission changes, new privileged accounts, unusual cron or service activity), and restrict low-privileged shell access to the server where possible. As the flaw is on CISA's KEV list, federal and BOD 26-04-bound stakeholders must apply vendor mitigations on internet-exposed and high-risk assets on an accelerated timeline. | — | — | KEV |
| moderatelikely thousands to tens of thousands of cPanel/WHM and Plesk hosting servers with the Acronis Backup integration installed |