discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis warns of a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk. The vulnerability may be exploited in the wild.

By Bill Toulas·Sep 15·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Acronis warns of actively exploited flaw in its cPanel backup plugin
Image: bleepingcomputer.com

Acronis has disclosed a critical vulnerability in its backup plugin for cPanel, WHM, and Plesk. The flaw could allow attackers to escalate privileges and access sensitive data.

Why it matters

This vulnerability could enable attackers to compromise web hosting environments, posing a significant risk to web hosting companies and server administrators.

This is like if someone found a secret door in your house that lets them become the boss of your whole neighborhood. The company that made the door knows about it and is telling everyone to fix it quickly to keep bad guys from using it.

Analysis

{"heading":"Technical Details of CVE-2026-87886","subheading":"Privilege Escalation Vulnerability","paragraphs":["CVE-2026-87886 is a local privilege escalation vulnerability affecting Acronis Backup plugin for cPanel, WHM, and Plesk. The vulnerability allows a low-privileged attacker to increase their permission level on a vulnerable Linux server.","The vulnerability was identified in Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638.","Acronis has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory."]}

Key points

  • Acronis warns of a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk.
  • The vulnerability affects Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638.
  • Users are recommended to apply the available updates immediately to protect their systems.
The Upside

Users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately to protect their systems.

The Downside

If the vulnerability is exploited, attackers could gain control over sensitive data and disrupt the system without user interaction.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityweb-hostinglinuxprivilege-escalationcpanel

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 15, 2026

Source

bleepingcomputer.com

Share

Topics

securityweb-hostinglinuxprivilege-escalationcpanel

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.