Acronis warns of actively exploited flaw in its cPanel backup plugin
Recorded: Sept. 15, 2026, 10 p.m.
| Original | Summarized |
Acronis warns of actively exploited flaw in its cPanel backup plugin News Featured Hackers hijack HBO Max Reddit account to push malware in ClickFix ads Homebrew 7.0.0 gets built-in GUI, better security controls Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent New Android malware encrypts files, steals data, and harasses victims Acronis warns of actively exploited flaw in its cPanel backup plugin Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites Cover 10 devices with 5 years of AdGuard VPN for $34.97 CenterPoint Energy confirms customer data stolen in cyberattack Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityAcronis warns of actively exploited flaw in its cPanel backup plugin Acronis warns of actively exploited flaw in its cPanel backup plugin By Bill Toulas September 15, 2026 Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Acronis Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft releases emergency Windows updates to fix RDS failures Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Microsoft: September updates cause RDS failures on Windows Server Sponsor Posts Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. Patch automation needs more than speed. Action1 brings control into every stage of deployment. Overdue a password health-check? Audit your Active Directory for free Watch a working exploit hit live controls and see exactly what blocks, detects, or misses EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Acronis has issued a warning regarding a high-severity Linux local privilege escalation vulnerability present in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk installations, which is reportedly being actively exploited in the wild. This vulnerability is identified as CVE-2026-87886 and is assigned a severity score of 7.8. The flaw allows a low-privileged attacker to escalate their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt system operations without requiring user interaction. Acronis indicated that their assessment is based on a single report from a potentially affected customer and has not disclosed specific indicators of compromise or the timeline of exploitation, choosing instead to provide time for system administrators to apply patches. The vulnerability specifically affects versions of Acronis Backup plugin for cPanel & WHM that build earlier than version 1.9.3.1021, which is corrected in version 1.9.3 HF3, and similarly affects the Acronis Backup extension for Plesk builds earlier than version 1.8.11.638, fixed in version 1.8.11. All users utilizing Acronis backup integrations for these hosting control panels are strongly advised to apply the available updates immediately to mitigate this risk. The advisory notes that exploitation of this vulnerability has been detected in limited, targeted attacks against Acronis Backup plugin deployments. The company has refrained from publishing further technical details to ensure that system administrators have adequate time to implement the necessary security patches before additional information is released. |