CVE Tools
Back to feed
Exploited in the wild Backup plugin for cPanel & WHM privilege-escalation Backup extension for Plesk Acronis web-app

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

Acronis has released urgent fixes for CVE-2026-87886, an insecure file permissions vulnerability exploited in targeted attacks against the Backup plugin for cPanel & WHM. The flaw can enable local privilege escalation in Linux versions before build 1.9.3.1021 and also affects the Backup extension for Plesk before build 1.8.11.638, though exploitation has not been reported for Plesk; administrators should update immediately.