Skip to content
Acronis Backup Plugin Vulnerability CVE-2026-87886 Exploited in Targeted Attacks

Acronis Backup Plugin Vulnerability CVE-2026-87886 Exploited in Targeted Attacks

First seen 16 Sep 2026, 10:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 11:54 UTC
  • CVE-2026-87886 allows local privilege escalation on Linux servers.
  • Exploitation detected in targeted attacks against Acronis Backup plugin for cPanel.
  • Administrators are urged to apply patches immediately to mitigate risks.

Acronis has disclosed a high-severity local privilege escalation vulnerability (CVE-2026-87886) in its backup plugin for cPanel and Plesk, which is actively being exploited in targeted attacks. The flaw allows low-privileged authenticated attackers to escalate their permissions on vulnerable Linux servers without user interaction. Acronis has identified exploitation in the wild, particularly against the cPanel & WHM deployments, but has not confirmed any active exploitation on Plesk systems. The vulnerability affects Acronis Backup plugin for cPanel & WHM versions earlier than 1.9.3.1021 and Acronis Backup extension for Plesk versions earlier than 1.8.11. Acronis has released patches for the affected versions and urges users to apply them immediately. Further technical details are withheld to allow administrators time to secure their systems. The CVSS score for this vulnerability is 7.8, indicating a high severity level.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
CVE-2026-87886 disclosed
Acronis published an advisory about the local privilege escalation vulnerability in its backup plugin.
BleepingComputer
2026-09-14
CVE-2026-76461 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
Patches released for affected versions
Acronis released updates for the Backup plugin for cPanel & WHM and Plesk to address CVE-2026-87886.
Helpnetsecurity
2026-09-16
Active exploitation confirmed
Acronis confirmed that the vulnerability is being exploited in targeted attacks against its Backup plugin for cPanel.
Helpnetsecurity

More articles in this cluster (3)

Following this threat?

Track Cisco and CVE-2026-76461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed