CVE Tools

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

SecurityWeekBy Ionut Arghire

Reported exploitedBackup plugin for cPanel & WHMBackup extension for Plesk

Our summary

Acronis has released urgent fixes for CVE-2026-87886, an insecure file permissions vulnerability exploited in targeted attacks against the Backup plugin for cPanel & WHM. The flaw can enable local privilege escalation in Linux versions before build 1.9.3.1021 and also affects the Backup extension for Plesk before build 1.8.11.638, though exploitation has not been reported for Plesk; administrators should update immediately.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store