Back Securityweek Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Acronis on Tuesday rolled out urgent patches for a vulnerability in the Backup plugin for cPanel & WHM that has been exploited in the wild.
The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments.
Insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges.
The vulnerability is tracked as CVE-2026-87886 (CVSS score of 7.8) and has been exploited in the wild against the plugin, but not against the extension.
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory .
The company says all Linux versions of the Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638 are affected.
Acronis has not shared technical details on the vulnerability but urges users to update their deployments immediately.
Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Related: Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
Exein Secures $270M at $1.7B Valuation for Physical AI Security
Thai Broadband Provider Hacked via Fortinet Vulnerability
240,000 Hit by Data Breach at Japan’s Digital Agency
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Hacked HBO Max Account Used for Malware Delivery via ClickFix Attack
Personal, Financial Info Exposed in Revolut Data Breach
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Hackuity Raises $19 Million for AI-Powered Vulnerability Management
280,000 Impacted by Premier Medical Group Data Breach
Chrome, Firefox Updates Patch 115 Vulnerabilities
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
“We Think the Security Control Is Working” Is No Longer Good Enough
$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws
Virtual Event: Attack Surface Management Summit 2026
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Webinar: Building Continuous Authorization at Scale
Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
