importantSYS.SOURCE: The Hacker News• 2026-09-16T16:38:54+05:30
Acronis cPanel Backup Plugin Privilege Escalation Vulnerability Exploited in Targeted Attacks
A high-severity privilege escalation vulnerability (CVE-2026-87886) in Acronis cPanel Backup Plugin was exploited in targeted attacks, allowing unauthorized access through insecure file permissions. Users are urged to apply urgent updates to mitigate risks.
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.
The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions -
Acronis Backup plugin for cPanel & WHM (Linux
*** END OF TRANSMISSION ***