Acronis on Tuesday rolled out urgent patches for a vulnerability in the Backup plugin for cPanel & WHM that has been exploited in the wild.
The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments.
Insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges.
The vulnerability is tracked as CVE-2026-87886 (CVSS score of 7.8) and has been exploited in the wild against the plugin, but not against the extension.
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory.
The company says all Linux versions of the Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638 are affected.
Acronis has not shared technical details on the vulnerability but urges users to update their deployments immediately.
Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Related: Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
