Skip to main content
Emerging ThreatsMalware & Ransomware

Acronis Plugin Vulnerability Exploited in Targeted Attacks

Linux server room with racks of equipment and a prominent workstation showing a generic Linux desktop.

"This update contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users," Acronis warned in an advisory accompanying its 1.9.3 HF3 update.

CVE-2026-87886: local privilege escalation through insecure file permissions

Acronis has confirmed a high-severity vulnerability in its Backup plugin for cPanel and Web Host Manager (WHM) and an affected extension for Plesk. The flaw is tracked as CVE-2026-87886 and carries a CVSS score of 7.8. Acronis describes the issue as a local privilege escalation caused by insecure file permissions on Linux deployments of the affected products.

According to Acronis and reporting by The Hacker News, a successful exploit could allow an attacker with low privileges to escalate those permissions on a vulnerable Linux system, potentially enabling unauthorized actions or execution of arbitrary code that could affect the confidentiality and integrity of the backup application.

Affected builds and the fix issued in 1.9.3 HF3

The company lists the impacted builds explicitly. The Acronis Backup plugin for cPanel & WHM (Linux) is affected in versions before build 1.9.3.1021; Acronis says the issue is fixed in 1.9.3 HF3. The Acronis Backup extension for Plesk (Linux) is affected in builds prior to 1.8.11.638. Acronis' advisory for 1.9.3 HF3 pairs the technical fix with a clear operational instruction: install the update immediately.

Observed exploitation: limited, targeted attacks; many details remain unknown

Acronis and subsequent reporting note that exploitation of CVE-2026-87886 has been "detected in the wild in limited, targeted attacks." The public record at this time does not include technical indicators, attribution, or stated objectives of the attackers. The Hacker News has contacted Acronis for comment and said it will update its coverage if the vendor responds.

The advisory itself does not provide specifics about when the activity was detected or how long the vulnerability may have been exploited prior to the fix being issued.

What this means for cPanel administrators, Plesk customers, and security teams

  • cPanel and WHM administrators: Systems running Acronis Backup plugin builds earlier than 1.9.3.1021 should be upgraded to the 1.9.3 HF3 release immediately to close the reported insecure file-permissions vulnerability.
  • Plesk customers using the Acronis Backup extension: Deployments with builds older than 1.8.11.638 are listed as affected and should be updated to the fixed build without delay.
  • Security teams responsible for affected Linux hosts: Because the vulnerability enables local privilege escalation, teams should assume that unpatched systems with low-privilege users or services exposed to potential adversaries are at higher risk and prioritize patching in accordance with the vendor's advisory.

Practical implications and remaining questions

The immediate practical step is straightforward: apply the vendor-supplied updates. Beyond that, the situation presents unanswered but concrete operational questions. The advisory confirms in-the-wild exploitation but gives no IOC, timeline, or adversary motive. That absence leaves defenders with limited ability to detect whether their systems have already been touched by the activity Acronis reported.

For administrators who cannot apply the update instantly, compensating controls — such as restricting access to affected systems, monitoring for unusual privilege changes, and reviewing local user activity — are implicit mitigations, though the advisory itself emphasizes installation of the update as the primary corrective action.

In sum: Acronis has patched CVE-2026-87886 in specific builds of its Backup plugin and extension after confirming limited, targeted exploitation. Customers running affected versions are advised to install the named fixes immediately; beyond that, the public record does not yet reveal who exploited the flaw, what they sought to accomplish, or exactly when the activity began.

Original reporting: The Hacker News — Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks