Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.

Acronis warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.
Acronis says it has detected exploitation of the vulnerability in the wild, "in limited, targeted attacks." “Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns .
It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux
Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces.
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.
The flaw was published in a brief advisory last weekend, but the company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8.
Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information.
The CVE-2026-87886 vulnerability affects the following product versions: The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory.
The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions.
In a statement for BleepingComputer, Acronis notes that the assessment is based on a single report from a "potentially affected" customer.
What you need to know
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.
Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces.
What security teams should do
The flaw was published in a brief advisory last weekend, but the company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8.
Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.