Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Summary
Acronis has issued a warning about a high-severity vulnerability in its Backup plugin for cPanel and WHM. This flaw, identified as CVE-2026-87886, allows for local privilege escalation due to insecure file permissions and has reportedly been exploited in targeted attacks.
IFF Assessment
The exploitation of a vulnerability allowing local privilege escalation poses a direct threat to system integrity and data security, making it bad news for defenders.
Severity
The CVSS score of 7.8 indicates a high-severity vulnerability, primarily due to the potential for local privilege escalation, which allows an attacker with initial access to gain higher-level permissions on the affected system.
Defender Context
This incident highlights the importance of promptly patching third-party plugins, especially those handling backups and critical infrastructure like cPanel/WHM. Defenders should prioritize identifying and securing instances of the vulnerable Acronis plugin and monitor for any signs of exploitation related to privilege escalation.