Cyber Resilience
← All news
Corroborated

Acronis warns of actively exploited flaw in its cPanel backup plugin

Our takeAcronis warns of an actively exploited local privilege escalation (CVE-2026-87886) in its cPanel/WHM backup plugin due to insecure file permissions. Patch it now if you run the plugin.
Sources (4)
What this means for you — Security leader:Update the Acronis cPanel/WHM backup plugin to the latest version on all affected Linux hosts immediately; the flaw allows local privilege escalation and is confirmed exploited in the wild.
What this means for you — Lean IT orgs:If you use Acronis Backup for cPanel or WHM on a Linux server, update the plugin right away — the vulnerability lets someone with server access escalate privileges and it is already being used in attacks.
What this means for you — MSP:Check every client Linux server running the Acronis cPanel/WHM backup plugin and push the update now; CVE-2026-87886 is a local privilege escalation actively exploited in targeted attacks.
What this means for you — Researcher:Acronis disclosed CVE-2026-87886 (CVSS 7.8), a local privilege escalation in its cPanel/WHM backup plugin due to insecure file permissions; the flaw is confirmed exploited in the wild.