CTIPilot
← Back to Daily brief 2026-09-18
HIGHCVE-2026-87886exploitedNATOB2vulnerability

CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)

Acronis's own hosting-panel backup plugin let a low-privilege local user escalate; CISA lists it as exploited on a single customer's report

Defender actions

  • Update the Acronis Backup plugin/extension on every cPanel & WHM (<1.9.3.1021) or Plesk (<1.8.11.638) server to the fixed build now, regardless of the single-customer-report basis behind Acronis's exploitation claim.

Analysis

CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file permissions (CWE-276) in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, both on Linux (Help Net Security, 2026-09-16). A local attacker who already holds low-privilege access on an affected hosting-panel server can escalate to elevated privileges by abusing the plugin's own file permissions; no remote or unauthenticated path is described. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline, and Acronis's advisory, quoted by both Help Net Security and BleepingComputer, states exploitation has been detected "in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments" (BleepingComputer, 2026-09-15); Acronis itself told BleepingComputer that assessment rests on a single report from a "potentially affected" customer, not a broadly observed campaign, and has published no indicators. Help Net Security states there are currently no signs of active exploitation on Plesk deployments specifically, so the confirmed activity is limited to the cPanel & WHM plugin (Help Net Security, 2026-09-16). Fixed builds: cPanel & WHM plugin 1.9.3 HF3 (build 1.9.3.1021), Plesk extension build 1.8.11.638.

Cited evidence

Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments

Acronis (via BleepingComputer)

the assessment is based on a single report from a 'potentially affected' customer

BleepingComputer 2026-09-15

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.