Helpnetsecurity Acronis Backup Plugin Vulnerability CVE-2026-87886 Exploited in Targeted Attacks
Article Content
- •CVE-2026-87886 allows local privilege escalation on Linux servers.
- •Exploitation detected in targeted attacks against Acronis Backup plugin for cPanel.
- •Administrators are urged to apply patches immediately to mitigate risks.
Acronis has disclosed a high-severity local privilege escalation vulnerability (CVE-2026-87886) in its backup plugin for cPanel and Plesk, which is actively being exploited in targeted attacks. The flaw allows low-privileged authenticated attackers to escalate their permissions on vulnerable Linux servers without user interaction. Acronis has identified exploitation in the wild, particularly against the cPanel & WHM deployments, but has not confirmed any active exploitation on Plesk systems. The vulnerability affects Acronis Backup plugin for cPanel & WHM versions earlier than 1.9.3.1021 and Acronis Backup extension for Plesk versions earlier than 1.8.11. Acronis has released patches for the affected versions and urges users to apply them immediately. Further technical details are withheld to allow administrators time to secure their systems. The CVSS score for this vulnerability is 7.8, indicating a high severity level.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Cisco and CVE-2026-76461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…