Acronis has issued a high-severity warning about a critical vulnerability in its cPanel backup plugin that is being actively exploited by attackers. The flaw, known as CVE-2026-87886, allows a low-privileged attacker to escalate their permission level on a vulnerable Linux server, potentially granting them access to sensitive data and disrupting the system.
The Acronis backup plugin is used by web hosting companies and server administrators to manage websites and servers through graphical interfaces. The plugin connects the hosting control panel to Acronis’ infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within cPanel and Plesk interfaces. However, the vulnerability in question allows an attacker to bypass security measures and gain higher-level access on a Linux server.
According to Acronis, exploitation of the vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. The company notes that this assessment is based on a single report from a “potentially affected” customer and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact.
The vulnerability affects specific versions of the Acronis backup plugin, including builds earlier than 1.9.3.1021 for cPanel & WHM and builds earlier than 1.8.11.638 for Plesk. The company has identified no specific indicators of compromise, but recommends that all affected users apply the available updates immediately to prevent exploitation.
Acronis’ warning serves as a reminder of the importance of regular security patches and updates in preventing attacks. As more organizations move their operations online, vulnerabilities like this one can have serious consequences if left unaddressed. In this case, attackers may be able to access sensitive data or disrupt critical systems, causing significant downtime and financial losses.
To protect against this vulnerability, users should check the version of their Acronis backup plugin immediately and apply any available updates. Regularly monitoring system logs for suspicious activity can also help detect potential attacks in real-time. Furthermore, organizations should consider implementing robust security measures, such as intrusion detection systems and regular vulnerability scans, to identify and address potential weaknesses before they are exploited.
By taking proactive steps to secure their systems, organizations can mitigate the risk of attacks like this one and prevent significant disruptions to their operations.
Source: Bleeping Computer — 2026-09-15