LIVE · cybersecurity feed
Live wire
vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

zeroday.news ·

Acronis has issued a warning about a high-severity local privilege escalation vulnerability, identified as CVE-2026-87886, affecting its backup plugins for cPanel & WHM and Plesk. The company states that this flaw is being actively exploited in targeted attacks.

The vulnerability, which carries a CVSS score of 7.8, allows a low-privileged attacker on a Linux server to elevate their permissions without user interaction. This could potentially enable unauthorized access to sensitive data, modification of system configurations, or disruption of services.

Acronis backup plugins integrate with cPanel & WHM and Plesk, which are widely used control panels for managing web hosting accounts and servers. These plugins allow administrators to perform backup and restoration operations for websites, files, databases, and mailboxes directly through the control panel interfaces.

According to Acronis, the observed exploitation of CVE-2026-87886 has been limited to specific, targeted attacks against deployments of the Acronis Backup plugin for cPanel & WHM. The company's assessment of active exploitation is based on a single report from a customer who may have been affected.

The company has not released specific indicators of compromise, nor has it disclosed the timeline of the attacks or the full extent of what attackers achieved beyond the privilege escalation. Further technical details about CVE-2026-87886 are being withheld to allow system administrators sufficient time to apply patches before more information is publicly available.

The vulnerability impacts Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021. The fix is available in version 1.9.3 HF3. For the Acronis Backup extension for Plesk, builds earlier than 1.8.11.638 are affected, with the patch included in version 1.8.11.

Acronis strongly recommends that all users of the affected backup integrations for cPanel & WHM and Plesk apply the available updates immediately to mitigate the risk of exploitation.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s