THREAT OPS › Threat News › Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.
The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions -
Acronis Backup plugin for cPanel & WHM (Linux
Indicators of compromise
- CVE-2026-87886cve
Original source: https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html