Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
ID: 69c0f7ff-ed7e-574b-a670-efa48629d51c
STIX ID: report--69c0f7ff-ed7e-574b-a670-efa48629d51c
Feed Name: Help Net Security
Threat Score
Acronis disclosed CVE-2026-87886, a local privilege escalation vulnerability in its backup plugins for cPanel & WHM and Plesk caused by insecure file permissions; limited targeted exploitation has been observed against the cPanel & WHM plugin. Acronis released updates (cPanel & WHM 1.9.3 HF3 and Plesk 1.8.11) and recommends administrators install them immediately; details of the observed in-the-wild attacks have not been published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
