Interestana
Home/News/Acronis cPanel Backup Plugin Vulnerability Exploited
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Acronis cPanel Backup Plugin Vulnerability Exploited

Acronis cPanel Backup Plugin Vulnerability Exploited

Acronis has issued a security alert regarding a high-severity vulnerability within its Backup plugin designed for cPanel and Web Host Manager (WHM) environments. This flaw, identified as CVE-2026-87886, has a CVSS score of 7.8, classifying it as a significant security risk. The vulnerability is characterized as a local privilege escalation issue stemming from insecure file permissions. Acronis has confirmed that this vulnerability has already been exploited in targeted attacks in the wild, indicating active malicious activity. The affected versions of the Acronis Backup plugin for cPanel & WHM on Linux systems include all versions prior to the release of the patched update. The company has not specified the exact number of affected customers or the nature of the targeted attacks beyond stating they are "targeted." However, the exploitation of this vulnerability could allow an attacker with local access to the cPanel or WHM server to gain elevated privileges. This could potentially lead to unauthorized access to sensitive data, system compromise, or further malicious actions on the server. Acronis strongly advises all users of the affected plugin to update to the latest version immediately to mitigate the risk. The company has released a patch to address the vulnerability and is urging administrators to apply it as a critical security measure. Web hosting providers and users relying on cPanel and WHM for server management are particularly at risk if they have not yet updated their Acronis Backup plugin. The exploitation of such vulnerabilities underscores the importance of timely security patching and diligent monitoring of server environments. Acronis, a global leader in cyber protection, offers solutions for data protection, disaster recovery, and cybersecurity. cPanel and WHM are widely used control panel software packages that simplify the management of web hosting servers. The exploitation of this specific vulnerability highlights a common attack vector where attackers leverage misconfigurations or flaws in administrative tools to gain deeper access to systems. The company's advisory emphasizes the need for immediate action to prevent potential data breaches or system disruptions. Administrators are encouraged to verify their plugin version and apply the update provided by Acronis. Further details regarding the technical specifics of the vulnerability and the patch are available through Acronis's official security advisories and support channels. The company's proactive warning aims to empower users to protect their infrastructure against ongoing threats.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next