A vulnerability in Acronis Backup, identified as CVE-2026-87886, was actively exploited two days before its official CVE publication, according to multiple vulnerability tracking sources. The flaw, an incorrect default permissions vulnerability, affects the Acronis Backup plugin for cPanel & WHM and the extension for Plesk, potentially allowing for privilege escalation.
The CVE was reserved on September 9, 2026, and officially published on September 17, 2026. However, the earliest record of its exploitation appeared on September 15, 2026, leaving no window for organizations to patch before attacks began.
The vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, the EU Vulnerability Database (EUVD) from ENISA, and VulnCheck KEV, all listing it as exploited. CISA added it to its KEV catalog on September 16, 2026, with a federal fix due date of September 19, 2026. The EUVD also listed it on September 16, 2026, while VulnCheck KEV recorded it a day earlier, on September 15, 2026.
Acronis itself confirmed public exploitation evidence, with an advisory published on September 15, 2026. CISA has advised affected organizations to apply mitigations in accordance with vendor instructions, adhering to its BOD 26-04 guidance for prioritizing security updates and forensics triage requirements. For cloud services, CISA recommends following applicable BOD 26-04 guidance or discontinuing product use if mitigations are unavailable.
The vulnerability is rated with a high severity, though a specific CVSS score was not immediately available. Its Exploit Prediction Scoring System (EPSS) score is 0.23%, placing it in the 12.8th percentile.






