CVE-2026-87886

LOW

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Deep dive

Full discourse16 posts
  • The Hacker News@TheHackersNews

    ⚠️ Acronis Backup flaw exploited in limited targeted attacks. CVE-2026-87886 lets a low-privileged attacker escalate permissions on affected Linux cPanel/WHM and Plesk deployments. Fixes are available. Which builds need updating → https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

    100814.8K
    2.3M followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    Acronis disclosed CVE-2026-87886 in its cPanel, WHM, and Plesk backup plugins: a Linux local privilege escalation flaw (CVSS 7.8) already used in limited targeted attacks. #Acronis #cPanel #Plesk https://www.hendryadrian.com/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/

    00030322
    4.7K followersView on X
  • Orion84@Orion84x

    Acronis: actively exploited LPE in Backup plugin for cPanel/WHM/Plesk (CVE-2026-87886, CVSS 7.8). Limited targeted hits. Update cPanel plugin to 1.9.3 HF3+ and Plesk ext to 1.8.11+. Hosting MSPs: treat as priority. #CyberSecurity #InfoSec #CVE Link: https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/

    2000021
    6 followersView on X
  • The Daily Tech Feed@dailytechonx

    Just uncovered: Acronis Backup plugin for cPanel/WHM has a serious privilege escalation flaw (CVE-2026-87886), now being exploited in targeted attacks. Versions before build 1.9.3.1021 (cPanel) and 1.8.11.638 (Plesk) are vulnerable. Fix with updates to 1.9.3 HF3 or newer. Key players: file permissions, root access, host integrity. Protect your hosting now. #Security #Vulnerability #Acronis #cPanel #PrivilegeEscalation #CVE2026 https://thedailytechfeed.com/critical-acronis-cpanel-plugin-flaw-being-exploited-in-the-wild/

    000004
    719 followersView on X
  • مستر حكيم@dsoajh

    يُعد اكتشاف الثغرة الأمنية CVE-2026-87886 في نظام أكرونيس باك أب تذكيراً مهماً بأهمية تحديث البرمجيات بانتظام، خاصةً في الأنظمة الحساسة مثل cPanel وWHM وPlesk. تتيح هذه الثغرة المهاجِمين ذوي الامتيازات المنخفضة تصعيد مستوياتهم، مما قد يؤدي إلى عواقب وخيمة على أمان الشبكة. من الضروري أن يقوم المسؤولون عن الأنظمة المتأثرة بفحص عمليات التحديث الفورية وتطبيق الإصلاحات المتاحة لتجنب أي استغلال محتمل. إن الحفاظ على تحديث البرمجيات هو ممارسة أساسية في إدارة الأنظمة الآمنة، حيث يقلل من نقاط الضعف المحتملة التي يمكن للمتسللين استغلالها. للحصول على معلومات مفصلة حول الأنظمة المتأثرة وكيفية التحديث، يُنصح بزيارة المواقع الرسمية لمطوري cPanel وWHM وPlesk. https://x.com/dsoajh/status/2097946271298232701?s=20

    0000019
    128 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub

    Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/?utm_source=dlvr.it&utm_medium=twitter

    00000431
    195.0K followersView on X
  • Shah Sheikh@shah_sheikh

    Acronis Patches Exploited Vulnerability in cPanel Backup Plugin: CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation. The post Acronis Patches Exploited Vulnerability in cPanel Backup Plugin… https://www.securityweek.com/acronis-patches-exploited-vulnerability-in-cpanel-backup-plugin/?utm_source=dlvr.it&utm_medium=twitter https://t.co/qluOjIodij

    0000016
    2.3K followersView on X
  • Shah Sheikh@shah_sheikh

    Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886): A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the… https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/?utm_source=dlvr.it&utm_medium=twitter https://t.co/qXhaggbfFj

    0000013
    2.3K followersView on X
  • Help Net Security@helpnetsecurity

    Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) - https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/ - @Acronis #Backup #Linux #MSP #Plugin #SecurityUpdate #Vulnerability #WebHosting #Cybersecurity #CybersecurityNews https://t.co/8kHMAFm1ne

    00000253
    60.2K followersView on X
  • ITフレブル【実務派エンジニア速報】@eng_digest_jp

    【バックアップ製品でも安全とは限らない】 ・CVE-2026-87886、深刻度7.8 ・低権限からLinux権限を上げる ・cPanelやPlesk管理者が対象 更新が急務です。報道によると悪用懸念もあります。 #CVE https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/

    0000016
    3 followersView on X
  • Arnaud Wallon@arwallon

    Acronis alerte : une faille activement exploitée dans ses extensions de sauvegarde cPanel et Plesk https://numeribrain.com/posts/acronis-cve-2026-87886-cpanel-plesk-exploitee

    0000015
    360 followersView on X
  • TechSignal@tchsignal

    Acronis Patches High-Severity Backup Plugin Flaw Amid Exploitation Warning Acronis has patched CVE-2026-87886, a high-severity local privilege-escalation vulnerability affecting its backup integrations for cPanel & WHM and Plesk on Linux. The flaw, rated CVSS 7.8, is linked to insecure file permissions. An attacker needs low-privileged access to an affected server first, so this is not an unauthenticated remote takeover. Successful exploitation can then allow privilege escalation without user interaction. Acronis says it detected exploitation in limited, targeted attacks involving cPanel & WHM deployments. That warning deserves an important caveat: the company told BleepingComputer that its assessment was based on one report from a potentially affected customer. There is currently no public evidence establishing a widespread campaign, and Acronis has not published specific indicators of compromise. For administrators, the immediate issue is therefore clear even while the scale of exploitation remains uncertain. Acronis has released fixed builds for both integrations and recommends updating affected installations. Plesk is confirmed vulnerable, but current public reporting does not establish that the observed exploitation also targeted Plesk deployments. #Cybersecurity #cPanel

    0000019
    15 followersView on X
  • Abijita Foundation@OfficialAbijita

    Acronis Warns of Actively Exploited Linux Privilege Escalation Flaw https://www.abijita.com/acronis-cve-2026-87886-linux-vulnerability/

    0000032
    516 followersView on X
  • SecNews@SecNews_GR

    Κρίσιμη ευπάθεια Acronis Backup: Ενεργές επιθέσεις σε cPanel και Plesk https://www.secnews.gr/733464/acronis-backup-cve-2026-87886/?fsp_sid=12651

    00000119
    7.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting CVE-2026-87886 to escalate privileges on hosting infrastructure running Acronis cPanel backup plugins. Active campaigns demonstrate how compromised hosting environments enable lateral movement across customer systems. Runtime segmentation helps contain post-compromise activity in multi-tenant hosting architectures. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/acronis-cpanel-backup-plugin-cve-2026-87886-privilege-escalation-2026

    0000031
    2.0K followersView on X
  • Windows Forum@windowsforum

    🚨 Acronis’ Linux backup flaw can grant local users elevated privileges. cPanel admins need build 1.9.3.1021+; Plesk users 1.8.11.638+. Patch now—backup shouldn’t backfire. https://windowsforum.com/news/cve-2026-87886-acronis-cpanel-fix-is-build-1-9-3-1021.444528/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #Acronis #Plesk #CpanelWhm #Cve202687886 https://t.co/p99AsgJ6NE

    0000027
    1.4K followersView on X

Explore more