Technology

Acronis CVE-2026-87886: cPanel and Plesk Backup updates after CISA KEV addition

CVE-2026-87886 affects Acronis Backup cPanel and Plesk integrations. Check fixed releases, local-access scope, targeted cPanel exploitation and the federal KEV deadline.

Original editorial illustration of a hosting administrator applying a security update across backup servers
Original editorial illustration of a hosting administrator applying a security update across backup servers. Illustration: Reddy News.
Key points
  • CISA added CVE-2026-87886, an Acronis Backup incorrect-default-permissions vulnerability, to its Known Exploited Vulnerabilities Catalog on 16 September 2026.
  • Acronis says it detected in-the-wild exploitation in limited, targeted attacks against its Backup plugin for cPanel & WHM deployments; it does not report Plesk exploitation.
  • Affected Linux integrations are the Acronis Backup cPanel & WHM plugin before build 1.9.3.1021 and Plesk extension before build 1.8.11.638.
  • Acronis directs cPanel & WHM users to version 1.9.3 HF3 and Plesk users to version 1.8.11. The flaw is a local privilege escalation requiring local access and low privileges.
  • CISA’s 19 September date is a BOD 26-04 deadline for in-scope U.S. federal civilian systems, not a private-sector patch deadline, though the KEV addition is a strong prioritisation signal.

CISA adds CVE-2026-87886 to KEV as Acronis reports targeted exploitation

Hosting administrators using Acronis Backup integrations for cPanel & WHM or Plesk should check their Linux plugin or extension version and move to the fixed release named by Acronis. The immediate news is that CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities Catalog on 16 September 2026, as Acronis disclosed limited, targeted exploitation against Acronis Backup plugin for cPanel & WHM deployments. The affected cPanel & WHM plugin should be updated to 1.9.3 HF3, while the affected Plesk extension should be updated to 1.8.11.

CVE-2026-87886 is not described as an unauthenticated internet-wide break-in. Acronis calls it a local privilege escalation due to insecure file permissions. Its published CVSS 3.0 vector gives the issue a 7.8 high score and specifies local attack vector, low attack complexity, low privileges required and no user interaction. In plain terms, the flaw matters when someone already has local access or a low-privilege foothold on an affected Linux server; the available evidence does not support describing it as a remote compromise of every exposed cPanel or Plesk site.

What CISA added on 16 September, and which updates were already available

CISA’s 16 September KEV addition is distinct from the earlier availability of the two fixed releases. Acronis’s update records show Acronis Backup plugin for cPanel & WHM 1.9.3 HF3 and Acronis Backup extension for Plesk 1.8.11 as already published. SEC-10986 supplies the CVE identifier, affected-build thresholds and warning about observed targeted exploitation. CISA’s KEV addition is a separate government prioritisation action; it does not add technical exploit details or convert the issue into a remote attack.

For operators, the practical conclusion is simple: an available update should not be deferred merely because the vulnerability begins locally. Hosting and managed-service environments can have multiple accounts, support paths and administrative tools on one server. A local privilege increase can therefore be consequential after another weakness, stolen account or authorised access has already given an intruder a foothold. That risk context is why a known-exploited designation merits urgent review without inflating what is known about the attack path.

Affected Acronis Backup cPanel & WHM and Plesk releases

Acronis SEC-10986 names two affected Linux components. The Acronis Backup plugin for cPanel & WHM is affected before build 1.9.3.1021; Acronis identifies version 1.9.3 HF3 as the update. The Acronis Backup extension for Plesk is affected before build 1.8.11.638; Acronis identifies version 1.8.11 as the update. These names and build boundaries matter because cPanel & WHM and Plesk are hosting-control-panel integrations, not a blanket statement about every Acronis backup product, every control-panel installation or non-Linux deployment.

Administrators should first inventory the Acronis component installed on each Linux host and record its version. Match cPanel & WHM systems to the cPanel plugin threshold and Plesk systems to the Plesk extension threshold. Then obtain and deploy the relevant Acronis fixed release through the organisation’s approved update process. A maintenance window, a current recovery plan and a post-update check of scheduled backup and restore functions help make a security update operationally safe without treating the update as proof that every prior server event was an intrusion.

Targeted cPanel exploitation does not mean Plesk exploitation

Acronis’s wording is deliberately narrower than a claim about both products: it says exploitation was detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. The advisory does not identify an attacker, victims, attack dates, entry route, indicators of compromise or what happened after privileges were raised. An independent report from Help Net Security likewise notes that the vendor had not disclosed attack details. Those missing facts are important boundaries, not reasons to postpone the listed updates.

Plesk remains in the remediation scope because its extension has the same advisory and a defined vulnerable-build range. But Acronis’s Plesk 1.8.11 update page says it sees no signs of active exploitation of the vulnerabilities listed there. That means an administrator should patch a vulnerable Plesk extension, while not reporting it as a confirmed exploitation case. CISA’s KEV entry also marks use in ransomware campaigns as unknown. Unknown is not evidence of ransomware use, or evidence that it was absent.

A focused update and review plan for hosting teams

Start with the hosts that run either affected Acronis Backup integration, especially shared, managed or business-critical Linux servers. Determine whether the installed cPanel & WHM plugin is earlier than 1.9.3.1021 or whether the Plesk extension is earlier than 1.8.11.638. Apply Acronis Backup plugin for cPanel & WHM 1.9.3 HF3 or Acronis Backup extension for Plesk 1.8.11 as appropriate. Retain the version evidence, change ticket and validation result so that the team can show which hosts were reviewed and which were updated.

After deployment, verify that the control-panel integration and the backup schedule still work as intended. Review normal administrative and security telemetry for unexpected account, permission or privileged-process changes on affected hosts according to the organisation’s incident process. CISA flags forensic triage for the KEV entry under its federal directive; private operators should use their own response procedures and escalation contacts rather than assume the entry supplies a universal investigation script. The public advisory does not provide indicators of compromise, so it cannot be used to declare a host clean or compromised on its own.

Teams coordinating a wider patch programme can compare this narrow local-access risk with Reddy News’s separate Cisco Secure Email Gateway CVE-2026-76461 coverage. Mac administrators handling a different local privilege issue can also consult the Parallels Desktop CVE-2026-90894 report in the Technology archive. The affected products, access conditions and update paths are different, so the related stories should not be treated as evidence that the same exposure or attack method applies across them.

Why the CISA KEV date matters differently for federal and private systems

CISA lists CVE-2026-87886 as added to KEV on 16 September with a 19 September due date. Its entry directs stakeholders to apply vendor mitigations in line with Binding Operational Directive 26-04 and notes that forensic triage is required under that directive. The date is significant for the federal vulnerability-management process because a KEV listing reflects CISA’s view that the vulnerability has been exploited in the wild and should be prioritised among agency risks.

Binding Operational Directive 26-04 is compulsory for in-scope U.S. Federal Civilian Executive Branch agencies and their federal information systems. It is not a consumer or private-company deadline, and it does not automatically govern hosting providers outside that scope. A private hosting company, managed-service provider or site owner should still treat the CISA addition as a reason to accelerate inventory, patching and documented verification, but should set its action timetable through its own risk, service and change-management responsibilities.

What is still unknown about CVE-2026-87886

The verified public material establishes the affected Linux components, the fixed versions, the local and low-privilege conditions in Acronis’s CVSS vector, and limited targeted exploitation of the cPanel & WHM plugin. It does not establish the number of affected organisations, an attacker or campaign name, a precise detection date, an initial-access method, stolen data, service disruption, a ransomware connection or exploitation of the Plesk extension. The public CVE Program page was still in Reserved status at the source-check time, so it does not add a completed CVE record with technical details.

BleepingComputer reported that Acronis told the outlet its assessment was based on a single report from a potentially affected customer. That is useful independent reporting but was not detailed in SEC-10986, and Reddy News could not independently validate the underlying customer report. It reinforces the need to read “limited, targeted” as the vendor’s bounded statement, not as a measure of prevalence or a reason to predict the next campaign. No material 17 September update beyond the 16 September advisory and KEV actions was identified in the sources reviewed by the stated cutoff.

Reader guide

Article questions, answered

Short answers to common reader questions based on the reporting above.

Which Acronis Backup versions need attention for CVE-2026-87886?

Acronis lists the Linux Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Linux Backup extension for Plesk before build 1.8.11.638 as affected. The stated target releases are Acronis Backup plugin for cPanel & WHM 1.9.3 HF3 and Acronis Backup extension for Plesk 1.8.11. Administrators should identify the installed integration and its version rather than assume that every Acronis product or every cPanel/Plesk server is in scope.

Is CVE-2026-87886 an unauthenticated remote attack on any web server?

No. Acronis describes a local privilege-escalation vulnerability caused by insecure file permissions. Its CVSS vector specifies local access and low privileges, with no user interaction required. That is serious on an affected Linux host, especially after an attacker has some foothold, but it does not establish unauthenticated, internet-wide remote compromise of a server merely because it runs cPanel, WHM or Plesk.

Has Acronis said that Plesk deployments are being exploited?

No. Acronis’s SEC-10986 advisory says it detected limited, targeted exploitation against Acronis Backup plugin for cPanel & WHM deployments. The Plesk extension is affected and should be updated, but its 1.8.11 update page says Acronis sees no signs of active exploitation of vulnerabilities listed there. That is a status statement at the source-check time, not a guarantee that activity cannot emerge later.

Does CISA’s 19 September 2026 due date apply to a private hosting company or managed-service provider?

No. The date in the CISA Known Exploited Vulnerabilities entry is a remediation deadline under Binding Operational Directive 26-04 for systems operated by in-scope U.S. Federal Civilian Executive Branch agencies. It is not a legal deadline for private-sector operators, customers outside that scope or ordinary website owners. CISA’s listing is still a useful risk-prioritisation signal for other organisations.

What should an administrator do after installing the Acronis Backup update?

Record the installed version and the hosts covered, confirm that scheduled backup and restore functions still operate as expected, and keep change records. Because this is a local privilege-escalation issue reported as exploited in limited targeted attacks, security teams should also follow their normal incident-review process for unexpected account, permission or administrative changes on affected hosts. The published material does not provide indicators of compromise, attacker identity, a victim count or evidence of ransomware use, so those should not be inferred from the KEV listing.

Sources and further reading

These references support the factual context used in this article. Links open the original publisher.

  1. SEC-10986: Local privilege escalation due to insecure file permissionsAcronis Advisory Database · accessed 17 September 2026
  2. Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3Acronis Advisory Database · accessed 17 September 2026
  3. Acronis Backup extension for Plesk version 1.8.11Acronis Advisory Database · accessed 17 September 2026
  4. Known Exploited Vulnerabilities CatalogCybersecurity and Infrastructure Security Agency · accessed 17 September 2026
  5. BOD 26-04: Prioritizing Security Updates Based on RiskCybersecurity and Infrastructure Security Agency · accessed 17 September 2026
  6. Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)Help Net Security · accessed 17 September 2026
  7. Acronis warns of actively exploited flaw in its cPanel backup pluginBleepingComputer · accessed 17 September 2026
  8. CVE-2026-87886CVE Program · accessed 17 September 2026