Acronis issues urgent patch for cPanel backup plugin

Acronis released patches for CVE-2026-87886 after limited attacks on its Backup plugin for cPanel; affected Linux builds are before 1.9.3.1021 and Plesk before 1.8.11.638.

Acronis released urgent patches on Tuesday to fix a vulnerability in its Backup plugin for cPanel & WHM that has been exploited in limited, targeted attacks.

The issue is tracked as CVE-2026-87886 and carries a CVSS score of 7.8. Acronis identified insecure file permissions in the Backup plugin and in the Backup extension for Plesk as the root cause. Those permissions can allow attackers to gain elevated privileges on affected systems.

Acronis listed the affected builds as all Linux versions of the Backup plugin for cPanel & WHM before 1.9.3.1021 and the Backup extension for Plesk before 1.8.11.638. The company reported active exploitation only against the cPanel plugin; the Plesk extension has not been observed abused in the wild.

The vendor deployed fixes and urged administrators to install the patched builds immediately. The advisory did not include technical details of the flaw but provided build numbers and mitigation guidance. Administrators are advised to update affected systems, review logs for signs of compromise and monitor for unusual activity.

Insecure file permissions can let unauthorized users read, modify or execute files they should not access. In backup tools, such access can expose full system images and user data and enable privilege escalation.

The advisory states: ‘Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments.’ Acronis did not disclose the number of affected systems or the identity of the attackers.

Articles by this author