news.mlab.sh
Back to the feed
vulnerability

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

High
Summary

A zero-day vulnerability in the Acronis Backup plugin for cPanel & WHM has been actively exploited in the wild. Acronis has released patches to address the issue, urging users to update their systems immediately to prevent further attacks.

A zero-day vulnerability within the Acronis Backup plugin for cPanel & WHM has been exploited by attackers. The vulnerability allows attackers to gain elevated privileges within affected systems. The vulnerability is identified as CVE-2026-87886 and carries a CVSS score of 7.8, indicating a high risk. Acronis has released patches to address the issue, specifically for Linux versions of the Backup plugin before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638. The company states that exploitation has been detected in targeted attacks against Acronis Backup plugin deployments. Acronis has not disclosed the specific technical details of the vulnerability, but strongly recommends immediate updates to mitigate the risk.

Read the full article at SecurityWeek