{"id":626364,"date":"2026-09-16T11:20:11","date_gmt":"2026-09-16T11:20:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/626364\/"},"modified":"2026-09-16T11:20:11","modified_gmt":"2026-09-16T11:20:11","slug":"acronis-backup-plugin-flaw-exploited-in-targeted-attacks-cve-2026-87886","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/626364\/","title":{"rendered":"Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)"},"content":{"rendered":"<p>A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis\u2019 backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/09\/acronis-650.webp\" class=\"aligncenter\" alt=\"Acronis backup vulnerability CVE-2026-87886\" title=\"Acronis\"\/><\/p>\n<p>\u201cExploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel &amp; WHM deployments,\u201d Acronis said in the <a href=\"https:\/\/security-advisory.acronis.com\/advisories\/SEC-10986\" target=\"_blank\" rel=\"nofollow noopener\">security advisory<\/a> published on Tuesday.<\/p>\n<p>There\u2019s currently no signs of its active exploitation on Plesk deployments.<\/p>\n<p>What the backup plugins do<\/p>\n<p>Acronis is a cybersecurity and data protection technology company that\u2019s popular among web hosting providers and managed service providers, since its platform lets them offer backup and security to their clients under their own branding.<\/p>\n<p>Acronis\u2019 backup add-ons link cPanel &amp; WHM and Plesk \u2013 control panel platforms that make managing web servers and websites easier through a graphical interface \u2013 to Acronis\u2019 cloud infrastructure, allowing administrators to back up and recover sites, databases, mailboxes, etc.<\/p>\n<p>What to do<\/p>\n<p>CVE-2026-87886 stems from insecure file permissions and allows authenticated attackers to achieve local privilege escalation without any user interaction. <\/p>\n<p>The vulnerability\u2019s CVSS string indicates that it can be exploited in low complexity attacks, i.e., the attack doesn\u2019t require special conditions or circumstances beyond the attacker\u2019s control to succeed.<\/p>\n<p>Though Acronis pushed out <a href=\"https:\/\/security-advisory.acronis.com\/updates\/UPD-2609-3d72-20a7\" target=\"_blank\" rel=\"nofollow noopener\">security<\/a> <a href=\"https:\/\/security-advisory.acronis.com\/updates\/UPD-2609-efb0-50b2\" target=\"_blank\" rel=\"nofollow noopener\">updates<\/a> for the vulnerable backup plugins last week, it has yet to disclose details about the in-the-wild attacks. Thus, we don\u2019t know what the attackers are doing once they escalate their privileges on vulnerable Linux servers.<\/p>\n<p>Acronis has advised administrators to immediately install:<\/p>\n<p>Acronis Backup plugin for cPanel &amp; WHM version 1.9.3 HF3<br \/>\nAcronis Backup extension for Plesk version 1.8.11<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/09\/devider.webp\"\/><\/p>\n<p>Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. <a href=\"https:\/\/www.helpnetsecurity.com\/newsletter\/\" rel=\"nofollow noopener\" target=\"_blank\">Subscribe here!<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/09\/devider.webp\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis\u2019 backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is&hellip;\n","protected":false},"author":2,"featured_media":626365,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[122848,73540,61,60,37028,266045,121599,109329,80,30039,186150],"class_list":["post-626364","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-acronis","tag-backup","tag-ie","tag-ireland","tag-linux","tag-msp","tag-plugin","tag-security-update","tag-technology","tag-vulnerability","tag-web-hosting"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/626364","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=626364"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/626364\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/626365"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=626364"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=626364"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=626364"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}