Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Acronis cPanel Backup Plugin Vulnerability: A High-Severity Security Flaw Exploited in Targeted Attacks


Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild, with the vulnerability tracked as CVE-2026-87886. Customers are advised to apply the latest updates to stay protected.

  • The Acronis cPanel Backup Plugin has a high-severity security flaw (CVE-2026-87886) that has been exploited in targeted attacks.
  • The affected versions of the plugin are before build 1.9.3.1021 and 1.8.11.638.
  • Successful exploitation of this vulnerability could allow low-privilege attackers to escalate permissions and potentially run arbitrary code.
  • Acronis has warned that the exploitation of this vulnerability has been detected in the wild in limited, targeted attacks.
  • Clients are advised to apply the latest updates as soon as possible to stay protected.
  • The vulnerability highlights the importance of staying vigilant and up-to-date with the latest security patches.



  • The cybersecurity landscape continues to evolve, with new threats and vulnerabilities emerging on a daily basis. In recent times, a high-severity security flaw has been identified in the Acronis cPanel Backup Plugin, which has been exploited in targeted attacks. This vulnerability, tracked as CVE-2026-87886, has been described as a case of local privilege escalation due to insecure file permissions.

    The affected versions of the Acronis Backup plugin for cPanel & WHM (Linux) and Acronis Backup extension for Plesk (Linux) are before build 1.9.3.1021 and 1.8.11.638, respectively. Successful exploitation of this vulnerability could allow an attacker with low privileges to escalate their permissions on a susceptible Linux version, potentially enabling them to perform unauthorized actions or run arbitrary code that could impact the confidentiality and integrity of the application.

    Acronis has warned that the exploitation of this vulnerability has been detected in the wild in limited, targeted attacks. However, it is not clear when the activity was detected and since when the security flaw may have been exploited in the wild. The Hacker News has contacted Acronis for comment and will update the story if they hear back.

    Customers of the Acronis backup plugin are advised to apply the latest updates as soon as possible to stay protected. It is essential for users to take proactive measures to address this vulnerability and prevent potential security breaches.

    In recent times, we have witnessed numerous high-profile security breaches and exploits, with many of these incidents being linked to vulnerabilities in software and plugins. The Acronis cPanel Backup Plugin vulnerability is just the latest example of the importance of staying vigilant and up-to-date with the latest security patches.

    In this article, we will delve deeper into the Acronis cPanel Backup Plugin vulnerability, explore its implications, and provide guidance on how users can protect themselves from potential security breaches.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Acronis-cPanel-Backup-Plugin-Vulnerability-A-High-Severity-Security-Flaw-Exploited-in-Targeted-Attacks-ehn.shtml

  • https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

  • https://www.securityweek.com/acronis-patches-exploited-vulnerability-in-cpanel-backup-plugin/


  • Published: Wed Sep 16 08:19:07 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us