Executive Summary
A critical local privilege escalation vulnerability, CVE-2026-87886, has been identified in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk on Linux systems. This flaw, detailed in Acronis Security Advisory UPD-2609-3d72-20a7, is being actively exploited in the wild. The vulnerability allows a low-privileged attacker with local access to escalate privileges to root, potentially resulting in full system compromise. The United States Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation by adding this CVE to its Known Exploited Vulnerabilities (KEV) catalog on 2026-09-16. Immediate patching and mitigation are strongly advised to prevent unauthorized access and maintain the integrity of affected systems.
Technical Information
The vulnerability, tracked as CVE-2026-87886, affects the Acronis Backup plugin for cPanel & WHM (builds earlier than 1.9.3.1021) and the Acronis Backup extension for Plesk (builds earlier than 1.8.11.638) on Linux platforms. The core issue arises from incorrect default permissions or improper privilege separation within the affected plugins. Specifically, local users with shell or user account access can exploit these misconfigurations to escalate their privileges to root, bypassing standard security controls.
The attack vector is strictly local, meaning the attacker must already possess access to the target system, either through a compromised account or by leveraging another vulnerability to gain initial foothold. No user interaction is required for exploitation, and the vulnerability can be leveraged without the need for social engineering or phishing.
The vulnerability is classified as a Local Privilege Escalation (LPE) with a CVSS score of 7.8 (High). Exploitation enables attackers to access or modify sensitive data, install persistent backdoors, or disrupt system operations. While Acronis has not released full technical details to allow administrators time to patch, the risk of further exploitation remains high due to the confirmed in-the-wild attacks.
From a technical perspective, the flaw likely involves insecure file or directory permissions, setuid binaries, or improper handling of privileged operations within the plugin’s codebase. Attackers may exploit these weaknesses to execute arbitrary code with elevated privileges, potentially chaining this vulnerability with other local or remote exploits for broader impact.
Exploitation in the Wild
CISA has officially confirmed active exploitation of CVE-2026-87886 by including it in the KEV catalog as of 2026-09-16. This confirmation underscores the urgency of remediation, as vulnerabilities listed in the KEV catalog are known to be leveraged by threat actors in real-world attacks. According to Acronis, exploitation has been observed in limited, targeted attacks, with at least one customer reporting compromise. The attacks have resulted in privilege escalation to root on Linux servers running vulnerable plugin versions.
No public proof-of-concept (PoC) exploit code has been released as of this report, and no exploit scripts have been observed in open-source repositories or underground forums. However, the lack of public PoC does not diminish the risk, as exploitation has been confirmed by both the vendor and CISA.
APT Groups using this vulnerability
As of the time of writing, there is no public attribution of CVE-2026-87886 exploitation to any specific Advanced Persistent Threat (APT) group or known cybercrime syndicate. The observed exploitation appears to be limited and targeted, with no evidence linking the activity to established threat actors. Open-source intelligence and vendor advisories have not identified any APT campaigns leveraging this vulnerability. However, given the critical nature of the flaw and its inclusion in the CISA KEV catalog, it is plausible that sophisticated actors may incorporate this exploit into their toolkits in the near future.
Affected Product Versions
The following product versions are confirmed to be vulnerable based on open-source advisories and vendor disclosures:
Acronis Backup plugin for cPanel & WHM: All builds earlier than 1.9.3.1021 are affected. The issue is resolved in version 1.9.3 HF3 and later.
Acronis Backup extension for Plesk: All builds earlier than 1.8.11.638 are affected. The issue is resolved in version 1.8.11 and later.
Organizations running these versions on Linux systems are at immediate risk and should prioritize remediation.
Workaround and Mitigation
The primary mitigation is to upgrade the affected plugins to the latest secure versions provided by Acronis. Specifically, administrators should deploy Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 or later, and Acronis Backup extension for Plesk version 1.8.11 or later. These updates address the underlying permission and privilege separation issues.
In addition to patching, organizations should audit all user accounts and privilege assignments on affected servers, ensuring that only authorized personnel have shell access. Monitoring for unusual privilege escalation or root-level activity is recommended, as is reviewing system logs for signs of unauthorized access or privilege abuse.
If immediate patching is not feasible, consider restricting local access to the affected systems, disabling unnecessary user accounts, and implementing additional monitoring for suspicious activity. However, these are temporary measures and do not replace the need for a full update.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26-04 Prioritizing Security Updates Based on Risk and CISA’s Forensics Triage Requirements. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to patching guidelines.
Indicators of Compromise
The following caveat applies: Indicators of compromise (IOCs) are point-in-time and should be validated before enforcement. As of the time of writing, no public indicators of compromise related to CVE-2026-87886 have been published by Acronis or reputable third-party sources.
No public indicators of compromise were available at the time of writing.
References
Acronis Security Advisory UPD-2609-3d72-20a7, BleepingComputer: Acronis warns of actively exploited flaw in its cPanel backup plugin, HelpNetSecurity: Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886), TheHackerNews: Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks, Reddit: Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks, CISA KEV Catalog
Rescana is here for you
Rescana empowers organizations to proactively manage third-party risk with our advanced TPRM platform, providing continuous monitoring, automated risk assessments, and actionable intelligence to strengthen your cybersecurity posture. We are happy to answer questions at info@rescana.com.



