CVE Tools

Acronis warns of actively exploited flaw in its cPanel backup plugin

BleepingComputerBy Bill Toulas

Reported exploitedAcronis Backup plugin for cPanel & WHMAcronis Backup extension for Plesk

Our summary

Acronis has warned that CVE-2026-87886, a Linux local privilege-escalation flaw with a CVSS score of 7.8, has been used in limited targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. The vulnerability affects Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638, allowing a low-privileged attacker to raise permissions and potentially access or alter sensitive data. Acronis fixed the issue in Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 and Acronis Backup extension for Plesk version 1.8.11; administrators should update promptly.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store