What happened
Heads up: Acronis found a nasty bug in its backup add-ons for cPanel/WHM and Plesk. These add-ons let hosting panels talk to Acronis so admins can back up and restore sites, files, databases, mailboxes and whole hosting accounts from the control-panel UI. Unfortunately, a CVE-2026-87886 vulnerability lets a low-privileged user escalate privileges on Linux servers.
The company gave this flaw a severity score of 7.8 and warns it’s being used in the wild in limited, targeted attacks. To avoid tipping off attackers, Acronis has held back detailed technical write-ups for now so teams have time to patch systems.
Affected versions and what to do
Short version: if you run Acronis backup integrations for cPanel/WHM or Plesk, treat this as urgent.
- Acronis Backup plugin for cPanel & WHM: builds earlier than 1.9.3.1021 — fixed in version 1.9.3 HF3
- Acronis Backup extension for Plesk: builds earlier than 1.8.11.638 — fixed in version 1.8.11
Acronis says the assessment relied on a single customer report and that they haven’t found clear indicators of compromise to share publicly. Still, that doesn’t mean you should relax.
What you should do now: immediately apply updates to any affected plugin/extension versions, review server logs for strange activity, validate your backups, rotate credentials for exposed systems, and isolate or harden any host you suspect might be touched. If you’re unsure, contact your vendor or support team and treat any unusual access as suspicious until proven otherwise.
In short: patch fast, poke through logs, and keep calm but suspicious. These things rarely fix themselves by staring at them.