A high-severity privilege escalation vulnerability in the Acronis cPanel backup plugin has been added to CISA’s Known Exploited Vulnerabilities catalogue after the company confirmed active exploitation in what it describes as ‘limited, targeted attacks.’ Tracked as CVE-2026-87886 with a severity score of 7.8, the flaw affects Acronis’s backup integrations for cPanel, WebHost Manager (WHM), and Plesk, the control panels that sit at the heart of a huge proportion of shared and managed web hosting infrastructure worldwide.

What CVE-2026-87886 actually does

The vulnerability is a Linux local privilege escalation bug: a low-privileged attacker who already has a foothold on a vulnerable server can use it to elevate their permissions, potentially gaining the ability to access or modify sensitive data and disrupt the system, all without requiring any user interaction. According to Vijilan, the root cause is insecure file permissions, formally classified as CWE-276 (Incorrect Default Permissions). That is a fairly unglamorous weakness (misconfigured permissions rather than a complex memory corruption bug) which makes it all the more frustrating for defenders, since these issues are typically preventable at build time.

Acronis published a brief advisory at the weekend before issuing a fuller update that formally assigned the CVE identifier and the 7.8 score. The company has withheld further technical details for now, reasoning that system administrators need time to patch before a more complete write-up hands attackers a roadmap. That is standard responsible-disclosure practice, though it does leave defenders working with limited information about exactly how the exploit works in practice.

Exploitation confirmed, but evidence is thin

Acronis says exploitation has been detected in the wild, but the picture is narrower than the headline might suggest. In a statement to BleepingComputer, the company acknowledged that its assessment rests on a single report from a ‘potentially affected’ customer. The advisory itself states that exploitation has occurred ‘in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,’ and Acronis has identified no specific indicators of compromise, nor disclosed when the activity occurred or what attackers achieved beyond the privilege-escalation impact described.

That said, CISA’s decision to add CVE-2026-87886 to its Known Exploited Vulnerabilities (KEV) catalogue carries real weight. Inclusion in the KEV list is not automatic; it signals that the agency has determined the vulnerability is being actively used against real targets, and it triggers mandatory patching deadlines for US federal civilian agencies. For everyone else, it is a strong prompt to treat this as a priority rather than a routine patch-cycle item.

According to a Threat Advisory Report, the vulnerability was first observed on 15 September 2026, which means there has been at least some window during which systems were potentially exposed before patches were widely publicised.

Affected versions and how to fix them

The Acronis cPanel backup plugin flaw affects two product lines. The Acronis Backup plugin for cPanel & WHM is vulnerable in all builds earlier than 1.9.3.1021, with the fix available in version 1.9.3 HF3. The Acronis Backup extension for Plesk is vulnerable in builds earlier than 1.8.11.638, fixed in version 1.8.11. Administrators running either integration should update immediately.

To understand why this matters at scale, it helps to recall what these plugins do. cPanel, WHM, and Plesk are graphical management interfaces used by web hosting companies and server administrators to run websites, databases, mailboxes, and hosting accounts. Acronis’s backup add-ons bolt onto those control panels to let administrators back up and restore all of that data from within the same interface. A privilege escalation flaw in that layer is particularly awkward: the plugin sits on servers that often host multiple customers, meaning a successful exploit on one tenant’s account could have consequences well beyond that single user. HivePro has also published a threat advisory on the vulnerability for teams that want additional context alongside Acronis’s own guidance.

Acronis’s advice is unambiguous: all affected users should apply the available updates without delay. Given the CISA KEV listing and the 15 September first-seen date, that window for comfortable deliberation has already closed.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version