A high-severity vulnerability has been discovered in Acronis’ backup plugin for popular web hosting control panels like cPanel and Plesk. The issue, known as CVE-2026-87886, allows a low-privileged attacker to escalate their permissions on a vulnerable Linux server, potentially granting them access to sensitive data or disrupting the system entirely.
Acronis has identified that this flaw is being actively exploited in limited, targeted attacks against its backup plugin for cPanel & WHM deployments. The company has detected these exploits in “potentially affected” customer environments, although it’s unclear when exactly this activity occurred or what specific goals the attackers were trying to achieve. What is clear, however, is that all users of Acronis’ backup integrations for cPanel & WHM and Plesk need to apply available updates as soon as possible.
So how does this vulnerability work? In brief, the issue arises when an attacker can take advantage of a misconfigured or outdated version of Acronis’ plugin. This allows them to bypass usual access controls and gain higher-level permissions on the affected system. With these elevated privileges, they could potentially modify sensitive data, delete critical files, or even gain full control over the server.
Acronis has confirmed that this vulnerability affects certain versions of its backup plugins for cPanel & WHM (builds earlier than 1.9.3.1021) and Plesk (builds earlier than 1.8.11). Thankfully, fixes are available – users should upgrade their plugins to version 1.9.3 HF3 or 1.8.11, respectively.
Acronis has chosen not to release further technical details on the vulnerability for now, preferring instead to give administrators time to apply patches before sharing more information. This decision reflects the company’s focus on prioritizing user security and minimizing the risk of further exploitation. In light of this development, it’s essential that all affected users – particularly those who use cPanel or Plesk – take immediate action to protect their systems.
As a practical takeaway for our readers, we recommend keeping your software up-to-date, especially when dealing with plugins and integrations from third-party vendors like Acronis. Regularly monitoring system logs and notifications will also help you detect any suspicious activity in a timely manner.
Source: Bleeping Computer — 2026-09-15