HomeSecurityCritical Acronis Backup Vulnerability: Active Attacks on cPanel and Plesk

Critical Acronis Backup Vulnerability: Active Attacks on cPanel and Plesk

Acronis Backup is at the center of a warning for CVE-2026-87886, a serious local elevation of privilege vulnerability in Linux that has been identified in limited, targeted attacks. The development affects cPanel, WHM, and Plesk installations and requires immediate patching.

According to BleepingComputer, Acronis identified the activity after receiving a report from a potentially affected customer. The company has not yet released technical details or specific indicators of the breach, to give administrators time to implement available fixes.

See also: Red Heron: Chinese group exploits critical vulnerability in Gitea

The Acronis Backup vulnerability and its scope

CVE-2026-87886 has a CVSS score of 7.8 and allows a low-privileged user to escalate their access level to the affected Linux server. Successful exploitation could lead to access or modification of sensitive data, as well as disruption of system operation, without requiring action from another user.

The issue is found in the Acronis Backup plugin for cPanel and WHM, as well as the Acronis Backup extension for Plesk. In hosting environments where multiple websites and accounts coexist on the same Linux server, a vulnerability in the permissions of a backup plugin can affect more than one customer.

Acronis Backup in cPanel and Plesk

Acronis says the exploit has been observed “in limited, targeted attacks.” The wording doesn’t document a widespread campaign, but it’s enough to make the issue a priority for hosting providers and teams managing multiple dashboards.

Who is affected by CVE-2026-87886?

In cPanel and WHM, builds of the Acronis Backup plugin older than 1.9.3.1021. The fixed version is available as 1.9.3 HF3. In Plesk, the issue affects builds earlier than 1.8.11.638, with version 1.8.11 containing the fix.

Version numbers must be checked separately for each installation, as an organization may use cPanel and Plesk at the same time. Simply updating the operating system is not enough if the Acronis Backup plugin remains on a vulnerable build.

Elevating privileges in Acronis Backup

See also: LiteSpeed ​​Enterprise: Critical vulnerability allows root access to shared servers

What should administrators do?

The key action is to immediately install the patched builds on all infrastructures using Acronis Backup. Administrators should log in to cPanel, WHM, and Plesk systems, check the version of each add-on, and confirm that the update completed without errors.

At the same time, you need to check the logs for unusual backup actions, configuration changes, or processes that were run with permissions different than expected. Acronis has not published specific indicators of compromise, so the search must be based on the normal profile of each server and each account.

Acronis Backup Update and Protection

If the update cannot be done immediately, the SecNews technical team recommends temporarily restricting access to the admin panels to trusted networks and disabling the add-on only after assessing the impact on recovery processes. Backups should remain available, but also protected from unauthorized access.

See also: ZcopyReaper: Critical vulnerability in Linux Kernel leads to root access

CVE-2026-87886 shows why backup management plugins should be treated as critical infrastructure components rather than utility tools. Until more information about the limited exploit is available, the safest option is to upgrade to patched versions and carefully monitor affected servers.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Particular care is needed in shared hosting environments. Elevating privileges from an account with limited access can turn a problem on a single website into a risk to other customers' data or to the server's own management functions.

After installing the update, security managers should re-run the permissions check, confirm that no old versions remain on backup nodes, and keep relevant logs available. The SecNews technical team also recommends changing any credentials used in suspicious sessions.

The absence of published indicators should not be taken as an indication that there is no risk. In a targeted attack, attackers may seek to remain discreet and avoid actions that immediately trigger alerts. For this reason, auditing should cover both dashboard applications and the operating system.

Hosting providers can leverage the opportunity for total control over segmentation, management accounts, and backup isolation. Maintaining separate, protected copies reduces the likelihood that a compromised account will lead to the loss or corruption of the only available copy.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS