Acronis has warned that CVE-2026-87886, a high-severity local privilege-escalation flaw (CVSS 7.8) in its Linux Backup plugin for cPanel & WHM and Backup extension for Plesk, has seen limited, targeted exploitation. Caused by insecure file permissions (CWE-276), the vulnerability lets an attacker who already has low-privileged local access elevate privileges without user interaction, potentially exposing or modifying backup data and system files or taking control of the hosting server.
Shared-hosting deployments face particular risk because a compromised tenant account could become a foothold for attacks against other customer accounts, services, and control-panel infrastructure. Acronis fixed the issue in cPanel & WHM plugin version 1.9.3 HF3 and Plesk extension version 1.8.11; administrators should update immediately and investigate affected systems for persistence or compromise artifacts, as patching prevents new exploitation but does not remove an existing attacker.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Acronis disclosed CVE-2026-87886, a CVSS 7.8 local privilege-escalation flaw caused by insecure file permissions in its Linux cPanel & WHM and Plesk backup integrations. It fixed affected products in Backup plugin for cPanel & WHM version 1.9.3 HF3 and Backup extension for Plesk version 1.8.11, urging administrators to update immediately.
Acronis reported limited, targeted in-the-wild exploitation of CVE-2026-87886 against its Backup plugin for cPanel & WHM. Its assessment was based on a single report from a potentially affected customer, and the scale of exploitation remains unknown.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceheise.de
Open sourcebleepingcomputer.com
Open sourcesecurity-advisory.acronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.