Overview
Acronis has disclosed a high-severity vulnerability affecting its backup integrations for cPanel & WHM and Plesk, warning that the flaw may already be under active exploitation. Tracked as CVE-2026-87886, the vulnerability carries a severity score of 7.8 and allows a low-privileged attacker to escalate permissions on a vulnerable Linux server. The affected plugins connect hosting control panels to Acronis backup infrastructure, allowing administrators to protect and restore websites, databases, mailboxes and hosting accounts. For IT leaders, the concern goes beyond a vulnerable plugin. Backup systems sit at the centre of recovery and resilience strategies, which makes them particularly valuable targets when attackers want to increase the impact of a compromise.
Why Privilege Escalation Matters
CVE-2026-87886 is a local privilege-escalation vulnerability, meaning an attacker first needs some level of access to the affected Linux environment. Once exploited, however, that attacker may be able to increase their permissions and gain access to sensitive information or perform actions that would normally be restricted. Acronis has not yet published detailed technical information, giving administrators time to deploy the available fixes before more information becomes public. This is important because privilege escalation often turns a limited compromise into a much more serious incident.
Exploitation Has Already Been Detected
Acronis says it has identified exploitation of the vulnerability in limited, targeted attacks involving the Acronis Backup plugin for cPanel & WHM. The company says its assessment is currently based on a report from a potentially affected customer, so the true scale of exploitation remains unclear. The lack of widespread exploitation should not reduce the urgency. Once vulnerability details become more widely understood, attackers may begin looking for additional vulnerable systems.
What Administrators Should Do
Affected environments should be updated immediately. The vulnerable Acronis Backup plugin for cPanel & WHM is fixed in version 1.9.3 HF3, while the affected Plesk extension is fixed in version 1.8.11. Acronis has not provided specific indicators of compromise, meaning organisations should also review privileged account activity, unusual processes, unexpected configuration changes and suspicious access around hosting and backup infrastructure. Backup platforms should also have tightly controlled administrative access, strong authentication and independent monitoring wherever possible.
Backup Infrastructure Is Part of the Security Perimeter
Backup technology is sometimes treated primarily as an operational tool. In reality, it is part of the organisation’s security architecture. Backup platforms may have privileged access to servers, databases, applications and large volumes of sensitive data. If attackers compromise that infrastructure, they could potentially interfere with recovery, access protected information or weaken the organisation’s ability to respond to ransomware. This is why modern cyber-resilience strategies should protect the backup system itself, not simply rely on it to protect everything else.
Expert in the Cloud Insight
CVE-2026-87886 reinforces an important lesson for CIOs, IT managers and security leaders: backup is not only a recovery function — it is a privileged security platform. Organisations often ask whether their backups are working and whether they can restore successfully. They should also be asking: “Who can access the backup platform, how is it monitored, and what happens if it becomes compromised?” Resilience depends on more than having copies of data. It requires protecting the identities, infrastructure and management systems responsible for creating and restoring those copies. A backup cannot be your last line of defence if the backup platform itself becomes part of the attack path.
Leave a Reply