CVE-2026-87886 — a high-severity Linux local privilege‑escalation flaw — was disclosed by Acronis this week and the vendor says it has been exploited in the wild in “limited, targeted attacks.”
CVE-2026-87886: Acronis' disclosure and what was detected
Acronis published a brief advisory over the weekend and issued an update today identifying the vulnerability as CVE-2026-87886 with a CVSS severity score of 7.8. The company warned that “Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments.” In a statement for BleepingComputer, Acronis said that its assessment is based on a single report from a “potentially affected” customer.
The vendor also said it has identified no specific indicators of compromise and did not disclose when the observed activity occurred or what attackers achieved beyond the privilege‑escalation impact described in the advisory.
Affected products and the fixed builds
The vulnerability affects Acronis' backup integrations for two hosting control-panel ecosystems:
- Acronis Backup plugin for cPanel & WHM — builds earlier than 1.9.3.1021; fixed in version 1.9.3 HF3.
- Acronis Backup extension for Plesk — builds earlier than 1.8.11.638; fixed in version 1.8.11.
The Acronis backup add-ons connect the hosting control panel to the company’s infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces. cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnical impact: what a local privilege escalation can allow
Acronis describes CVE-2026-87886 as a Linux local privilege-escalation vulnerability. A low-privileged attacker who can exploit this flaw can increase their permission level on a vulnerable Linux server, “potentially enabling them to access or modify sensitive data and disrupt the system without user interaction.”
Further technical details on CVE-2026-87886 have not been published by Acronis; the company said it is withholding those details to give system administrators time to apply the available patches before sharing more information.
Immediate action for system administrators and hosting companies
Acronis recommends that all affected users of its backup integrations for cPanel & WHM and Plesk apply the available updates immediately. Given the fixed builds the vendor published, that means:
- Upgrading any Acronis Backup plugin for cPanel & WHM installs to version 1.9.3 HF3 or later.
- Upgrading any Acronis Backup extension for Plesk installs to version 1.8.11 or later.
The vendor’s advisory also notes the absence of specific indicators of compromise, which complicates post‑incident detection and will leave administrators relying primarily on patching and configuration review until Acronis publishes further technical details.
How hosting providers, system administrators, and end users are affected
- Hosting providers: Because cPanel & WHM and Plesk are widely used to manage customer websites and servers, hosting companies running vulnerable Acronis backup add‑ons face a direct operational risk. They will need to prioritize installing the fixed builds and may need to coordinate with customers if remediation affects running services.
- System administrators: Administrators who manage Linux servers with the Acronis integrations should inventory plugin/extension builds immediately, apply the updates specified by Acronis, and monitor communications from the vendor for any subsequently released indicators of compromise or technical guidance.
- End users of hosted services: Although the advisory focuses on the hosting-side plugin, the documented impact — potential access to or modification of sensitive data — means end users should expect hosting providers to patch and to be prepared to ask providers whether their environments were updated and whether any investigation was performed.
The record Acronis has published is concise: a named CVE, fixed builds, a severity score of 7.8, and a warning that limited targeted exploitation has been observed based on a single report. Administrators and hosting companies have the concrete step Acronis encourages — install the updated plugin and extension builds — while awaiting the vendor’s promised additional technical detail and any indicators that would help determine whether specific systems were compromised.




