NG Solution Team
Cybersecurity

Acronis Backup plugin for cPanel patched after active exploitation

Acronis on Tuesday rolled out urgent patches for a vulnerability in the Acronis Backup plugin for cPanel & WHM that has been exploited in the wild.

The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments. Acronis says insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges.

“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory.

Acronis Backup plugin: affected builds and exploitation

The vulnerability is tracked as CVE-2026-87886 and carries a CVSS score of 7.8. Acronis reports the flaw has been exploited in the wild against the Backup plugin for cPanel & WHM, but not against the Backup extension for Plesk.

According to the advisory, all Linux versions of the Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638 are affected. Acronis has not shared technical details on the vulnerability but urges users to update their deployments immediately.

Related posts

Chrome urgent update: restart now to patch zero-day CVE-2026-85046

Emily Brown

Why is the government worried about usernames on messaging apps?

Jessica Williams

Scams Target Seniors: AG Warns of Gold Bar Scheme as Amherst Seniors Stay Alert

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy