Acronis has warned about a high-severity security vulnerability in its backup plugins for cPanel, WebHost Manager (WHM), and Plesk that is being exploited in limited, targeted attacks.
The vulnerability, tracked as CVE-2026-87886, affects Acronis backup integrations used by hosting companies and server administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts through cPanel and Plesk.
Acronis published an initial advisory about the flaw last weekend and has now assigned it a CVE identifier and a severity score of 7.8. The company has not yet released detailed technical information about the vulnerability, giving administrators time to install the available security updates.
CVE-2026-87886 is a local privilege escalation vulnerability affecting Linux servers. A low-privileged attacker could exploit the flaw to increase their permissions on an affected system. Depending on the access gained, this could allow sensitive data to be accessed or modified and could potentially disrupt the server without requiring additional user interaction.
The vulnerability is particularly concerning because Acronis says it has already detected exploitation in the wild. The company described the activity as limited and targeted attacks against deployments of its Backup plugin for cPanel and WHM.
However, Acronis said its assessment is based on a single report from a potentially affected customer. The company has not disclosed when the attacks took place or what attackers achieved beyond the privilege escalation described in its advisory. It also says it has not identified any specific indicators of compromise at this time.
The affected products include Acronis Backup plugin for cPanel and WHM builds earlier than 1.9.3.1021, which are fixed in version 1.9.3 HF3. The Acronis Backup extension for Plesk is affected in builds earlier than 1.8.11.638 and has been fixed in version 1.8.11.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Acronis is urging administrators using its backup integrations with cPanel, WHM, or Plesk to apply the available updates immediately. Since the company has confirmed limited exploitation, updating affected installations is important for reducing exposure while further technical details remain unpublished



