A vulnerability in Acronis Backup, identified as CVE-2026-87886, was exploited in the wild at least two days before its public disclosure. The flaw, described as an incorrect default permissions vulnerability, affects the Acronis Backup plugin for cPanel & WHM and the extension for Plesk, and could lead to privilege escalation.
The vulnerability was first listed in a Known Exploited Vulnerabilities (KEV) catalog on September 15, 2026, while the CVE was officially published on September 17, 2026. Both the U.S. federal CISA KEV and the European Union's ENISA EUVD listed the vulnerability as exploited on September 16, 2026. A commercial research KEV from VulnCheck also reported exploitation on September 15, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87886 to its KEV catalog on September 16, 2026, with a federal fix deadline of September 19, 2026. CISA advises organizations to apply mitigations in accordance with vendor instructions and to evaluate the internet exposure of affected assets. If mitigations are unavailable, CISA recommends discontinuing use of the product.
Acronis confirmed the exploitation and released a security advisory, SEC-10986, which was publicly available by September 15, 2026. The vulnerability has a "high" severity rating, though a specific CVSS score was not provided in the available information. The Exploit Prediction Scoring System (EPSS) for this CVE is 0.25%, placing it in the 17.4th percentile, suggesting a relatively low probability of exploitation despite confirmed in-the-wild activity.






