Hosting operators running Acronis backup tooling on Linux should patch now. The vendor confirms that a privilege escalation bug in its cPanel and Web Host Manager extensions is being abused in targeted attacks.
The flaw, CVE-2026-87886, scores 7.8 and traces to insecure file permissions. An attacker gains local privilege escalation without user interaction, and the scoring vector flags low attack complexity with no conditions beyond the attacker’s control.
Which builds need attention
Two product lines carry a fix. Administrators want the cPanel and WHM plugin at 1.9.3 HF3, and the Plesk extension at 1.8.11. Acronis pushed both updates last week.
Its advisory is direct about the risk: exploitation has been seen in the wild in limited, targeted attacks against cPanel and WHM deployments. Plesk installs have not shown the same activity.
What remains unknown is who is behind the campaign, what they pursue once privileges are raised, and how long the activity has run.
Scale is what makes this matter. Acronis is a common choice for web hosts and managed service providers that resell branded backup and recovery, so one compromised control panel node can sit above thousands of customer sites, mailboxes, and databases.
Patch the affected builds and sweep host logs for privileged activity that no administrator authorized.
