Protect.Computer
NEWS

Actively Exploited Flaw in Acronis cPanel Backup Plugin

· 1 min read · Device safety
Actively Exploited Flaw in Acronis cPanel Backup Plugin

Acronis has disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel & WHM and Plesk — two control panels used by tens of thousands of web hosting companies and server administrators worldwide. The flaw, tracked as CVE-2026-87886 with a CVSS score of 7.8, may already be actively exploited in the wild according to Acronis’s disclosure.

The vulnerability allows a low-privileged attacker who already has a foothold on a Linux server — for example, a compromised hosting account — to escalate their permissions to root level. From there, they can access or modify sensitive data belonging to any account on the same server, or disrupt the system entirely. Acronis has declined to publish further technical details for now to give administrators time to apply patches. No specific indicators of compromise (IoCs) have been shared.

How to check if you’re affected

Affected versions include the Acronis Backup plugin for cPanel & WHM at builds earlier than 1.9.3.1021, and the Acronis Backup extension for Plesk at builds earlier than 1.8.11.638. To check your installed build, log into your cPanel or Plesk server and review the installed plugin version in the extensions or add-ons panel. If your version is below these thresholds, update immediately: the fixed versions are 1.9.3 HF3 (for cPanel/WHM) and 1.8.11 (for Plesk).

Sources

Related reading