Exploited in the wild Backup plugin for cPanel & WHM privilege-escalation Backup extension for Plesk Acronis web-app
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
CVE Tools coverage
Acronis says CVE-2026-87886 is being exploited in targeted attacks against its Backup plugin for cPanel & WHM. Insecure file permissions let authenticated attackers elevate privileges locally on Linux servers; administrators should update the cPanel & WHM plugin to version 1.9.3 HF3 and the Backup extension for Plesk to version 1.8.11, though no Plesk exploitation has been observed.