Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a privilege escalation vulnerability CVE-2026-87886 (7.8) in its backup plugin for cPanel, WHM, and Plesk. The company recorded exploitation in targeted attacks; fixes were released in versions 1.9.3 HF3 and 1.8.11.
- CVE-2026-87886 rated 7.8 and allows privilege escalation on Linux servers
- Vulnerable plugin builds for cPanel/WHM up to 1.9.3.1021 and Plesk extension up to 1.8.11.638
- Acronis said exploitation occurred in limited targeted attacks
- Fixes released in versions 1.9.3 HF3 and 1.8.11
Read next
Security