Back Helpnetsecurity Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns.
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis said in the security advisory published on Tuesday.
There’s currently no signs of its active exploitation on Plesk deployments.
What the backup plugins do
Acronis is a cybersecurity and data protection technology company that’s popular among web hosting providers and managed service providers, since its platform lets them offer backup and security to their clients under their own branding.
Acronis’ backup add-ons link cPanel & WHM and Plesk – control panel platforms that make managing web servers and websites easier through a graphical interface – to Acronis’ cloud infrastructure, allowing administrators to back up and recover sites, databases, mailboxes, etc.
CVE-2026-87886 stems from insecure file permissions and allows authenticated attackers to achieve local privilege escalation without any user interaction.
The vulnerability’s CVSS string indicates that it can be exploited in low complexity attacks, i.e., the attack doesn’t require special conditions or circumstances beyond the attacker’s control to succeed.
Though Acronis pushed out security updates for the vulnerable backup plugins last week, it has yet to disclose details the in-the-wild attacks. Thus, we don’t know what the attackers are doing once they escalate their privileges on vulnerable Linux servers.
Acronis has advised administrators to immediately install:
Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3
Acronis Backup extension for Plesk version 1.8.11
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Attackers hijack HBO Max’s account for 48-hour malvertising blitz
What we know the Revolut data breach so far
Download: The High-Performance Team Playbook
Simplify security management with CIS SecureSuite Platform
Download: The IT and security field guide to AI adoption
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Attackers hijack HBO Max’s account for 48-hour malvertising blitz
What we know the Revolut data breach so far
Turn it off and on again, but for critical infrastructure
Permify: Open-source authorization as a service
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
