CVE Tools
Back to feed
Exploited in the wild Acronis Backup plugin for cPanel & WHM privilege-escalation Acronis Backup extension for Plesk Acronis cloud

Acronis warns of actively exploited flaw in its cPanel backup plugin

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Acronis has warned that CVE-2026-87886, a Linux local privilege-escalation flaw with a CVSS score of 7.8, has been used in limited targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. The vulnerability affects Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638, allowing a low-privileged attacker to raise permissions and potentially access or alter sensitive data. Acronis fixed the issue in Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 and Acronis Backup extension for Plesk version 1.8.11; administrators should update promptly.