Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation.

Zero-day vulnerability

Acronis on Tuesday rolled out urgent patches for a vulnerability in the Backup plugin for cPanel & WHM that has been exploited in the wild.

The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments.

Insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges.

The vulnerability is tracked as CVE-2026-87886 (CVSS score of 7.8) and has been exploited in the wild against the plugin, but not against the extension.

“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory.

The company says all Linux versions of the Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638 are affected.

Advertisement. Scroll to continue reading.

Acronis has not shared technical details on the vulnerability but urges users to update their deployments immediately.

Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Related: Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.