Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux
We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.
Also reported by 1 other outlet
- Acronis Patches Exploited Vulnerability in cPanel Backup Plugin securityweek.com