Acronis has published a high-severity security advisory for its hosting-control-panel backup integrations after detecting limited in-the-wild exploitation against cPanel deployments.
The advisory identifies CVE-2026-87886, a local privilege escalation issue caused by insecure file permissions. Acronis rates the flaw 7.8 CVSS and says exploitation has been observed in targeted attacks against the Acronis Backup plugin for cPanel & WHM.
The fixed builds listed by Acronis are 1.9.3.1021 for the cPanel & WHM plugin and 1.8.11.638 for the Acronis Backup extension for Plesk. Both products are Linux-hosted backup components commonly used by hosting providers, agencies and managed-server operators.
For hosting teams, the practical priority is to inventory servers with the Acronis cPanel plugin, confirm the patched build is installed, and review privileged local accounts and recent backup-agent activity where vulnerable versions were exposed. Plesk operators should also apply the listed extension update even though the advisory’s exploitation note specifically names cPanel deployments.
