Active exploitation claim triggers urgent patching
Acronis says it has observed at least one instance of CVE‑2026‑87886 being used in the wild, a local‑privilege‑escalation bug that lets an attacker with limited access on a Linux host running the backup plugin become root.
The flaw lives in the Acronis Backup plugin for cPanel/WHM and the extension for Plesk. It stems from improper handling of privileged operations in the plugin’s helper binary, allowing a low‑privilege user to invoke a set‑uid executable and gain full system rights.
CVSS 7.8 rates the issue as high severity. It affects:
- cPanel & WHM plugin builds older than 1.9.3.1021 (fixed in 1.9.3 HF3)
- Plesk extension builds older than 1.8.11.638 (fixed in 1.8.11)
Both products run on typical shared‑hosting Linux servers, meaning thousands of web‑hosting providers and their customers could be exposed.
Why it matters for you
Root access on a hosting server is a gateway to every site, database, and credential stored on that machine. An attacker could pivot to compromise hosted applications, exfiltrate data, or install ransomware.
What to do right now
- Verify your Acronis Backup version. If you’re on a cPanel/WHM build earlier than 1.9.3.1021 or a Plesk build earlier than 1.8.11.638, you’re vulnerable.
- Download and apply the latest Acronis patches (1.9.3 HF3 for cPanel/WHM, 1.8.11 for Plesk) from the official Acronis portal.
- Restart the backup services after updating to ensure the new binaries are loaded.
- Audit logs for any unexpected privileged command execution since the advisory’s release.
- Consider temporary mitigations such as restricting shell access to trusted accounts until the patch is applied.
While Acronis has not published concrete IOCs, the lack of detailed evidence means you should treat the claim as a strong signal to patch immediately.
