Infrastructure, domains & the recurring invoice of civilisation

The Hosting Ledger

Sharp briefings on web hosting, internet domains, cloud infrastructure and the fragile plumbing of being online.

Security

Acronis Patches Actively Exploited cPanel Backup Plugin Flaw

September 16, 2026 ·
Acronis Patches Actively Exploited cPanel Backup Plugin Flaw

Acronis has published a high-severity security advisory for its hosting-control-panel backup integrations after detecting limited in-the-wild exploitation against cPanel deployments.

The advisory identifies CVE-2026-87886, a local privilege escalation issue caused by insecure file permissions. Acronis rates the flaw 7.8 CVSS and says exploitation has been observed in targeted attacks against the Acronis Backup plugin for cPanel & WHM.

The fixed builds listed by Acronis are 1.9.3.1021 for the cPanel & WHM plugin and 1.8.11.638 for the Acronis Backup extension for Plesk. Both products are Linux-hosted backup components commonly used by hosting providers, agencies and managed-server operators.

For hosting teams, the practical priority is to inventory servers with the Acronis cPanel plugin, confirm the patched build is installed, and review privileged local accounts and recent backup-agent activity where vulnerable versions were exposed. Plesk operators should also apply the listed extension update even though the advisory’s exploitation note specifically names cPanel deployments.

Source: Acronis security advisory SEC-10986