Acronis backup add-on flaw already exploited on Linux hosts

A privilege escalation bug in Acronis backup extensions for cPanel and WHM is under limited, targeted attack against hosting infrastructure.

CSBadmin
2 Min Read

Hosting operators running Acronis backup tooling on Linux should patch now. The vendor confirms that a privilege escalation bug in its cPanel and Web Host Manager extensions is being abused in targeted attacks.

The flaw, CVE-2026-87886, scores 7.8 and traces to insecure file permissions. An attacker gains local privilege escalation without user interaction, and the scoring vector flags low attack complexity with no conditions beyond the attacker’s control.

Which builds need attention

Two product lines carry a fix. Administrators want the cPanel and WHM plugin at 1.9.3 HF3, and the Plesk extension at 1.8.11. Acronis pushed both updates last week.

Its advisory is direct about the risk: exploitation has been seen in the wild in limited, targeted attacks against cPanel and WHM deployments. Plesk installs have not shown the same activity.

What remains unknown is who is behind the campaign, what they pursue once privileges are raised, and how long the activity has run.

Scale is what makes this matter. Acronis is a common choice for web hosts and managed service providers that resell branded backup and recovery, so one compromised control panel node can sit above thousands of customer sites, mailboxes, and databases.

Patch the affected builds and sweep host logs for privileged activity that no administrator authorized.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.