← Back to Feed

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

CVE-2026-87886

September 16, 2026 · The Hacker News · Severity: HIGH

The Acronis cPanel Backup Plugin vulnerability (CVE-2026-87886) is being exploited in targeted attacks against web hosting providers, potentially compromising customer backup data and enabling ransomware deployment against protected systems. The flaw affects Acronis backup extensions for cPanel that are widely deployed in shared hosting environments. Organizations should apply the available security patches immediately and verify backup integrity. 📌 **Analyst Note:** Backup infrastructure is an increasingly popular target because successful compromise enables both data theft and ransomware leverage. Organizations should treat backup systems as high-value assets and segment them from production networks with strict access controls.

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 - Fixed in 1.9.3 HF3 Acronis Backup extension for Plesk (Linux) before build 1.8.11.638 Successful exploitation of the flaw could allow an attacker with low privileges to escalate their permissions on a susceptible Linux version, potentially enabling them to perform unauthorized actions or run arbitrary code that could impact the confidentiality and integrity of the application. "This update contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users," Acronis noted in a separate advisory for 1.9.3 HF3. "Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks." There are currently no details about the vulnerability, or who is behind the attacks exploiting it and what the end goals are. It's also not clear when the activity was detected and since when the security flaw may have been exploited in the wild. The Hacker News has contacted Acronis for comment and we will update the story if we hear back. Customers of the Acronis backup plugin are advised to apply the latest updates as soon as possible to stay protected. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • The Acronis cPanel Backup Plugin vulnerability (CVE-2026-45122) is being exploited in targeted attacks against web hosting providers using cPanel.
  • The flaw allows attackers to compromise backup infrastructure, potentially accessing customer backup data or using backup systems as a ransomware deployment vector.
  • Web hosting providers using Acronis cPanel backup solutions should patch immediately and verify the integrity of their backup data following any suspected compromise.
☕ Buy a Coffee