CVE Tools

Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

Help Net SecurityBy Zeljka Zorz

Reported exploitedBackup plugin for cPanel & WHMBackup extension for Plesk

Our summary

Acronis says CVE-2026-87886 is being exploited in targeted attacks against its Backup plugin for cPanel & WHM. Insecure file permissions let authenticated attackers elevate privileges locally on Linux servers; administrators should update the cPanel & WHM plugin to version 1.9.3 HF3 and the Backup extension for Plesk to version 1.8.11, though no Plesk exploitation has been observed.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store