Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Reported exploitedBackup plugin for cPanel & WHMBackup extension for PleskOur summary
Acronis has released urgent fixes for CVE-2026-87886, an insecure file permissions vulnerability exploited in targeted attacks against the Backup plugin for cPanel & WHM. The flaw can enable local privilege escalation in Linux versions before build 1.9.3.1021 and also affects the Backup extension for Plesk before build 1.8.11.638, though exploitation has not been reported for Plesk; administrators should update immediately.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.