Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

ONE SENTENCE SUMMARY:

Acronis reports CVE-2026-87886 in its cPanel/WHM Backup plugin is exploited, enabling local privilege escalation via insecure permissions.

MAIN POINTS:

  1. Acronis disclosed active exploitation of a high-severity flaw in its Backup plugin.
  2. Vulnerability is tracked as CVE-2026-87886 with a CVSS score of 7.8.
  3. Root cause involves insecure file permissions enabling local privilege escalation on Linux.
  4. Attackers need low-privilege access to escalate permissions on affected deployments.
  5. Exploitation could enable unauthorized actions or arbitrary code execution impacting confidentiality and integrity.
  6. Acronis says fixes are included in version 1.9.3 HF3 and urged immediate installation.
  7. Advisory notes exploitation has been observed in limited, targeted attacks in the wild.
  8. Public details about the vulnerability’s mechanics have not been released.
  9. Attribution for the attacks and adversary objectives remain unknown.
  10. Detection timeline and duration of exploitation activity have not been clarified.

TAKEAWAYS:

  1. Patch Acronis Backup plugin installations to 1.9.3 HF3 promptly to reduce risk.
  2. Treat low-privilege footholds on cPanel/WHM servers as potential escalation paths.
  3. Prioritize monitoring for suspicious privilege changes on Linux hosting environments.
  4. Assume targeted exploitation may expand, despite currently limited reporting.
  5. Maintain rapid update processes for hosting control panel plugins due to frequent attacker interest.