Acronis CVE-2026-87886: Update cPanel and Plesk Backup Plugins


Acronis has patched CVE-2026-87886, a high-severity local privilege-escalation vulnerability affecting its Linux backup integrations for cPanel & WHM and Plesk. Acronis says it detected limited, targeted exploitation against deployments of the cPanel & WHM plugin and recommends immediate updates.

The vulnerability carries a CVSS 3.1 score of 7.8 and stems from insecure file permissions. A low-privileged authenticated attacker can exploit the flaw locally to gain elevated privileges without user interaction, potentially enabling unauthorized actions or arbitrary code execution with greater permissions on the affected server.

For cPanel & WHM, affected Linux builds are earlier than 1.9.3.1021 and the fixed release is 1.9.3 HF3. For Plesk, builds earlier than 1.8.11.638 are affected and the fixed release is 1.8.11. Acronis has reported exploitation against the cPanel & WHM plugin; current reporting says the company has not identified exploitation against the Plesk extension.

Affected and fixed versions

Acronis integration Affected Linux builds Fixed release
Backup plugin for cPanel & WHM Earlier than 1.9.3.1021 1.9.3 HF3
Backup extension for Plesk Earlier than 1.8.11.638 1.8.11

Administrators running either integration should verify the installed build and update to the fixed release or a newer supported version. The privilege boundary matters particularly on multi-tenant hosting systems because an attacker who already controls a low-privilege account can use a local escalation flaw to expand access on the underlying Linux host.

Exploitation status

Acronis states that exploitation has been detected in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. The company's assessment, according to a statement provided to BleepingComputer, is based on a report from a potentially affected customer.

That distinction narrows the current evidence. The vulnerable Plesk extension should still be patched because it shares the CVE and affected-version disclosure, while the published in-the-wild activity currently concerns the cPanel & WHM plugin.

Acronis has not published specific indicators of compromise for CVE-2026-87886. The company has also withheld deeper technical details while administrators deploy the fixes. Operators investigating a potentially compromised hosting server should therefore preserve relevant system, authentication, process and control-panel telemetry and follow any newer incident-response guidance Acronis adds to its advisory.

Why the flaw matters on hosting servers

Acronis' cPanel and Plesk integrations connect hosting-control-panel environments with backup and recovery services. These systems commonly manage multiple sites, accounts, databases and mailboxes on the same Linux server.

CVE-2026-87886 requires an authenticated low-privilege position rather than an unauthenticated remote request. Its impact begins after an attacker has local access at that privilege level. Successful escalation can increase the damage available from an initial account or website compromise by crossing the server's intended privilege boundary.

The appropriate remediation is therefore to patch the Acronis component even when the control panel itself is current. cPanel, Plesk and the installed Acronis backup integration have separate update lifecycles.

Remediation priority

Acronis recommends immediate installation of 1.9.3 HF3 for the Backup plugin for cPanel & WHM and 1.8.11 for the Backup extension for Plesk. Hosting providers should inventory Linux servers using these integrations, confirm the installed build, update affected systems and give cPanel & WHM deployments additional investigation priority because Acronis has reported targeted exploitation there.

The current public evidence supports a focused response: patch both affected integrations and investigate cPanel & WHM systems where exposure or suspicious local activity warrants review. Further campaign details and product-specific indicators may change that investigation scope if Acronis publishes additional technical information.

Sources

  • Acronis Security Advisory Database: SEC-10986, CVE-2026-87886.
  • Acronis update advisory UPD-2609-3d72-20a7 for the affected backup integrations.
  • BleepingComputer: Acronis warns of actively exploited flaw in its cPanel backup plugin, September 15, 2026.
  • SecurityWeek: Acronis Patches Exploited Vulnerability in cPanel Backup Plugin, September 16, 2026.