Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
- ID
- 25030
- Status
- summarized
- Published
- 16 Sep 2026, 7:08 PM
- Fetched
- 16 Sep 2026, 8:26 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 16 Sep 2026, 8:30 PM
- Tags
- Audience
- developerssaas_founders
What happened
Acronis has disclosed CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in its Backup plugin for cPanel/WHM and Plesk on Linux, caused by insecure file permissions. The vulnerability is being exploited in limited, targeted attacks; affected builds are cPanel plugin versions before 1.9.3.1021 and Plesk extension versions before 1.8.11.638, with fixes available in 1.9.3 HF3.
Why it matters
If you run cPanel/WHM or Plesk hosting with the Acronis Backup plugin on Linux, update to 1.9.3 HF3 (cPanel) or build 1.8.11.638+ (Plesk) immediately — exploitation is confirmed in the wild and allows low-privilege users to escalate to arbitrary code execution. Malaysian web hosting providers and agencies managing client servers on cPanel are a likely affected group.
Discussion angle
How many Malaysian SMB hosting setups still run Acronis cPanel plugins, and do typical agency ops workflows include patching backup plugin components separately from cPanel auto-updates?