Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html
ONE SENTENCE SUMMARY:
Acronis reports CVE-2026-87886 in its cPanel/WHM Backup plugin is exploited, enabling local privilege escalation via insecure permissions.
MAIN POINTS:
- Acronis disclosed active exploitation of a high-severity flaw in its Backup plugin.
- Vulnerability is tracked as CVE-2026-87886 with a CVSS score of 7.8.
- Root cause involves insecure file permissions enabling local privilege escalation on Linux.
- Attackers need low-privilege access to escalate permissions on affected deployments.
- Exploitation could enable unauthorized actions or arbitrary code execution impacting confidentiality and integrity.
- Acronis says fixes are included in version 1.9.3 HF3 and urged immediate installation.
- Advisory notes exploitation has been observed in limited, targeted attacks in the wild.
- Public details about the vulnerability’s mechanics have not been released.
- Attribution for the attacks and adversary objectives remain unknown.
- Detection timeline and duration of exploitation activity have not been clarified.
TAKEAWAYS:
- Patch Acronis Backup plugin installations to 1.9.3 HF3 promptly to reduce risk.
- Treat low-privilege footholds on cPanel/WHM servers as potential escalation paths.
- Prioritize monitoring for suspicious privilege changes on Linux hosting environments.
- Assume targeted exploitation may expand, despite currently limited reporting.
- Maintain rapid update processes for hosting control panel plugins due to frequent attacker interest.