Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
High · The Hacker News ·
Exploited
What happened
Acronis warned CVE-2026-87886, a high-severity local privilege escalation flaw in its Backup plugin for cPanel/WHM Linux deployments, is exploited in targeted attacks.
What to do now
Apply the latest Acronis Backup plugin for cPanel/WHM update immediately; if no fixed version is listed, verify with the vendor advisory. Restrict local access, audit file permissions, and monitor for exploitation.
CVE references
- CVE-2026-87886
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.