Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis warns of actively exploited Linux privilege escalation flaw in its cPanel backup plugin.
Summary
Acronis has disclosed a critical Linux local privilege escalation vulnerability (CVE-2026-87886) in its backup plugin for cPanel, WHM, and Plesk. The flaw, with a severity score of 7.8, allows low-privileged attackers to gain elevated permissions on vulnerable servers. Acronis has detected exploitation of this vulnerability in limited, targeted attacks.
Full text
Acronis warns of actively exploited flaw in its cPanel backup plugin By Bill Toulas September 15, 2026 05:37 PM 0 Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces. Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces. The flaw was published in a brief advisory last weekend, but the technology company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8. A low-privileged attacker can exploit CVE-2026-87886 to increase their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction. Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information. Acronis says it has detected exploitation of the vulnerability in the wild, "in limited, targeted attacks." “Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns. In a statement for BleepingComputer, Acronis notes that the assessment is based on a single report from a "potentially affected" customer. The CVE-2026-87886 vulnerability affects the following product versions: Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021, fixed in version 1.9.3 HF3 Acronis Backup extension for Plesk builds earlier than 1.8.11.638, fixed in version 1.8.11 The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory. All affected users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: WordPress membership plugin bug exploited to create admin accountsHackers exploit critical Adobe Commerce flaw to hijack customer accountsHackers target WordPress sites via third-party WooCommerce pluginJapan's Digital Agency says VPN flaw exposed 246,000 personnel recordsArtifactory flaws chained in attacks deploying backdoor malware
Indicators of Compromise
- cve — CVE-2026-87886