First Seen: September 15, 2026
Affected Products: Acronis Backup plugin for cPanel & WHM (Linux); Acronis Backup extension for Plesk (Linux)
Impact: Acronis has disclosed CVE-2026-87886, a high-severity flaw in its Backup plugin for cPanel & WHM and its Backup extension for Plesk on Linux, and confirmed that attackers are already using it. The weakness comes down to insecure file permissions, which lets a local attacker who already holds a low-privileged, authenticated foothold raise their access level on the server without any user interaction. Because cPanel, WHM, and Plesk sit at the heart of how hosting providers and managed service providers run their users’ websites, databases, and mailboxes, a successful escalation on one of these servers can hand an attacker deep control over a shared hosting environment. Exploitation has been seen in the wild in limited, targeted attacks aimed at cPanel & WHM deployments, based on a report from a potentially affected user, while the Plesk extension has shown no signs of being attacked. Fixes are available, and given the confirmed exploitation, updating without delay is the safest course.
CVE
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | Acronis Backup plugin for cPanel & WHM / Acronis Backup extension for Plesk | No | No | Yes |
Vulnerability Details
Vulnerability
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-87886 | Acronis Backup plugin for cPanel & WHM (Before 1.9.3.1021); Acronis Backup extension for Plesk (Before 1.8.11.638) | cpe:2.3:a:acronis:backup_plugin_for_cpanel_and_whm:*:*:*:*:*:*:*:*cpe:2.3:a:acronis:backup_extension_for_plesk:*:*:*:*:*:*:*:* | CWE-276 |
Recommendations
Install the fixed builds without delay. For cPanel & WHM, upgrade the Acronis Backup plugin to version 1.9.3 HF3, and for Plesk, upgrade the Acronis Backup extension to version 1.8.11. Applying the vendor patches directly closes the vulnerability.
Active exploitation has been confirmed against cPanel & WHM deployments specifically, so patch those systems first. Plesk deployments should still be updated promptly, but the confirmed in-the-wild activity makes cPanel & WHM the higher-priority target.
Because the flaw is abused from an existing low-privileged, authenticated account, audit the local and hosting accounts on affected servers. Remove unnecessary or dormant accounts, tighten access to only what each user needs, and reset credentials where there is any doubt about their integrity.
Acronis has not published specific indicators of compromise, so rely on behavioral monitoring rather than static IoCs. Watch server and system logs for unexpected privilege changes, unusual process execution under elevated accounts, and unexplained modifications to backup files or configurations.
Maintain an accurate inventory of software versions and security patches, including third-party plugins and extensions that run on control-panel servers, and evaluate the security posture of vendors whose components run with elevated access.
Potential MITRE ATT&CK TTPs
Patch Links
- security-advisory.acronis.com — UPD-2609-3d72-20a7
- security-advisory.acronis.com — UPD-2609-efb0-50b2
- security-advisory.acronis.com — SEC-10986
References
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
