Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
A critical security vulnerability in the Acronis Backup plugin for cPanel and WHM has been actively exploited in targeted attacks. Users are urged to update immediately to prevent unauthorized access and potential data compromise.
A high-severity security vulnerability, identified as CVE-2026-87886 (CVSS score: 7.8), exists within the Acronis Backup plugin for cPanel and Web Host Manager (WHM). This vulnerability allows for local privilege escalation on susceptible Linux versions. The flaw stems from insecure file permissions, enabling an attacker with limited privileges to gain elevated access and potentially execute arbitrary code. Acronis has confirmed that exploitation of this vulnerability has been detected in the wild, though details regarding the attackers and their motives remain unknown. The vulnerability affects versions of the Acronis Backup plugin before build 1.9.3.1021, with a fix available in 1.9.3 HF3. Acronis advises all users to apply the latest updates without delay to mitigate the risk.
