← Back to Feed
Acronis warns of actively exploited flaw in its cPanel backup plugin
September 15, 2026 · BleepingComputer · Severity: HIGH
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.
Key Takeaways
- Acronis has warned customers about an actively exploited vulnerability in its cPanel backup solution that could allow attackers to compromise backup infrastructure.
- The flaw affects Acronis backup extensions for cPanel, potentially giving attackers access to backup data and the ability to deploy ransomware against protected systems.
- Organizations using Acronis cPanel backup should apply the available security patches immediately and verify backup integrity following the patch.