Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Summary

Acronis has issued a warning about a high-severity vulnerability in its Backup plugin for cPanel and WHM. This flaw, identified as CVE-2026-87886, allows for local privilege escalation due to insecure file permissions and has reportedly been exploited in targeted attacks.

IFF Assessment

FOE

The exploitation of a vulnerability allowing local privilege escalation poses a direct threat to system integrity and data security, making it bad news for defenders.

Severity

7.8 High

The CVSS score of 7.8 indicates a high-severity vulnerability, primarily due to the potential for local privilege escalation, which allows an attacker with initial access to gain higher-level permissions on the affected system.

Defender Context

This incident highlights the importance of promptly patching third-party plugins, especially those handling backups and critical infrastructure like cPanel/WHM. Defenders should prioritize identifying and securing instances of the vulnerable Acronis plugin and monitor for any signs of exploitation related to privilege escalation.

Read Full Story →