Skip to content
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

Helpnetsecurity September 16, 2026

A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns.

“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis said in the security advisory published on Tuesday.

There’s currently no signs of its active exploitation on Plesk deployments.

What the backup plugins do

Acronis is a cybersecurity and data protection technology company that’s popular among web hosting providers and managed service providers, since its platform lets them offer backup and security to their clients under their own branding.

Acronis’ backup add-ons link cPanel & WHM and Plesk – control panel platforms that make managing web servers and websites easier through a graphical interface – to Acronis’ cloud infrastructure, allowing administrators to back up and recover sites, databases, mailboxes, etc.

CVE-2026-87886 stems from insecure file permissions and allows authenticated attackers to achieve local privilege escalation without any user interaction.

The vulnerability’s CVSS string indicates that it can be exploited in low complexity attacks, i.e., the attack doesn’t require special conditions or circumstances beyond the attacker’s control to succeed.

Though Acronis pushed out security updates for the vulnerable backup plugins last week, it has yet to disclose details the in-the-wild attacks. Thus, we don’t know what the attackers are doing once they escalate their privileges on vulnerable Linux servers.

Acronis has advised administrators to immediately install:

Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3

Acronis Backup extension for Plesk version 1.8.11

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Attackers hijack HBO Max’s account for 48-hour malvertising blitz

What we know the Revolut data breach so far

Download: The High-Performance Team Playbook

Simplify security management with CIS SecureSuite Platform

Download: The IT and security field guide to AI adoption

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Attackers hijack HBO Max’s account for 48-hour malvertising blitz

What we know the Revolut data breach so far

Turn it off and on again, but for critical infrastructure

Permify: Open-source authorization as a service