Exploited in the wild Backup plugin for cPanel & WHM privilege-escalation Backup extension for Plesk Acronis web-app
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
CVE Tools coverage
Acronis says CVE-2026-87886 has been used in limited, targeted attacks against its Backup plugin for cPanel & WHM and Backup extension for Plesk. The insecure file permissions issue affects Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 and Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, allowing a low-privileged local attacker to elevate privileges and potentially run arbitrary code; update to 1.9.3 HF3 and the latest Plesk release.