Acronis Patches High-Severity Backup Plugin Flaw Amid Exploitation Warning
Acronis has patched CVE-2026-87886, a high-severity local privilege-escalation vulnerability affecting its backup integrations for cPanel & WHM and Plesk on Linux.
The flaw, rated CVSS 7.8, is linked to insecure file permissions. An attacker needs low-privileged access to an affected server first, so this is not an unauthenticated remote takeover. Successful exploitation can then allow privilege escalation without user interaction.
Acronis says it detected exploitation in limited, targeted attacks involving cPanel & WHM deployments. That warning deserves an important caveat: the company told BleepingComputer that its assessment was based on one report from a potentially affected customer. There is currently no public evidence establishing a widespread campaign, and Acronis has not published specific indicators of compromise.
For administrators, the immediate issue is therefore clear even while the scale of exploitation remains uncertain. Acronis has released fixed builds for both integrations and recommends updating affected installations. Plesk is confirmed vulnerable, but current public reporting does not establish that the observed exploitation also targeted Plesk deployments.
#Cybersecurity #cPanel