LmCast :: Stay tuned in

Acronis warns of actively exploited flaw in its cPanel backup plugin

Recorded: Sept. 15, 2026, 10 p.m.

Original Summarized

Acronis warns of actively exploited flaw in its cPanel backup plugin

News

Featured
Latest

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Homebrew 7.0.0 gets built-in GUI, better security controls

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

New Android malware encrypts files, steals data, and harasses victims

Acronis warns of actively exploited flaw in its cPanel backup plugin

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Cover 10 devices with 5 years of AdGuard VPN for $34.97

CenterPoint Energy confirms customer data stolen in cyberattack

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityAcronis warns of actively exploited flaw in its cPanel backup plugin

Acronis warns of actively exploited flaw in its cPanel backup plugin

By Bill Toulas

September 15, 2026
05:37 PM
0

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.
cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces.
Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces.
The flaw was published in a brief advisory last weekend, but the technology company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8.
A low-privileged attacker can exploit CVE-2026-87886 to increase their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction.
Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information.
Acronis says it has detected exploitation of the vulnerability in the wild, "in limited, targeted attacks."
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns.
In a statement for BleepingComputer, Acronis notes that the assessment is based on a single report from a "potentially affected" customer.
The CVE-2026-87886 vulnerability affects the following product versions:
Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021, fixed in version 1.9.3 HF3
Acronis Backup extension for Plesk builds earlier than 1.8.11.638, fixed in version 1.8.11
The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory.
All affected users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
WordPress membership plugin bug exploited to create admin accountsHackers exploit critical Adobe Commerce flaw to hijack customer accountsHackers target WordPress sites via third-party WooCommerce pluginJapan's Digital Agency says VPN flaw exposed 246,000 personnel recordsArtifactory flaws chained in attacks deploying backdoor malware

Acronis
Actively Exploited
Addons
Backup
cPanel
Local Privilege Escalation
Privilege Escalation
Vulnerability

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft releases emergency Windows updates to fix RDS failures

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Microsoft: September updates cause RDS failures on Windows Server

Sponsor Posts

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Overdue a password health-check? Audit your Active Directory for free

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Acronis has issued a warning regarding a high-severity Linux local privilege escalation vulnerability present in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk installations, which is reportedly being actively exploited in the wild. This vulnerability is identified as CVE-2026-87886 and is assigned a severity score of 7.8. The flaw allows a low-privileged attacker to escalate their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt system operations without requiring user interaction. Acronis indicated that their assessment is based on a single report from a potentially affected customer and has not disclosed specific indicators of compromise or the timeline of exploitation, choosing instead to provide time for system administrators to apply patches.

The vulnerability specifically affects versions of Acronis Backup plugin for cPanel & WHM that build earlier than version 1.9.3.1021, which is corrected in version 1.9.3 HF3, and similarly affects the Acronis Backup extension for Plesk builds earlier than version 1.8.11.638, fixed in version 1.8.11. All users utilizing Acronis backup integrations for these hosting control panels are strongly advised to apply the available updates immediately to mitigate this risk. The advisory notes that exploitation of this vulnerability has been detected in limited, targeted attacks against Acronis Backup plugin deployments. The company has refrained from publishing further technical details to ensure that system administrators have adequate time to implement the necessary security patches before additional information is released.