Threat Intelligence

Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin

The Hacker News · 16 Sept 2026
Key Takeaway If your business uses Acronis Backup for cPanel or WHM, update to the latest patched version immediately to close this actively exploited security gap.

Acronis has disclosed that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) is being actively exploited in the wild. The vulnerability, tracked as CVE-2026-87886 with a CVSS score of 7.8, stems from insecure file permissions on affected Linux versions of the plugin, allowing local privilege escalation.

According to Acronis, an attacker who already has low-level access to a vulnerable system could exploit the flaw to gain higher privileges, potentially running unauthorized code and compromising the confidentiality and integrity of the application. The company has released a fix in version 1.9.3 HF3 and confirmed that exploitation has already been detected in limited, targeted attacks, though details on the attackers or their motives have not been made public.

Acronis is urging all customers running the affected plugin to install the latest update immediately. Little is currently known about the scope or timeline of the attacks, and further details may emerge as the investigation continues.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.