← Back to Feed

Acronis warns of actively exploited flaw in its cPanel backup plugin

September 15, 2026 · BleepingComputer · Severity: HIGH

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.

Key Takeaways

  • Acronis has warned customers about an actively exploited vulnerability in its cPanel backup solution that could allow attackers to compromise backup infrastructure.
  • The flaw affects Acronis backup extensions for cPanel, potentially giving attackers access to backup data and the ability to deploy ransomware against protected systems.
  • Organizations using Acronis cPanel backup should apply the available security patches immediately and verify backup integrity following the patch.
☕ Buy a Coffee