Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Jeremy Greenwood denies giving ‘ridiculous’ evidence to Icac about ‘mum’s perspective’ from premier’s sister-in-law | Independent Commission Against Corruption

    September 16, 2026

    Vertrauensfrage à la Merz – POLITICO

    September 16, 2026

    We don’t need AI regulation — leave safety to us, Nvidia’s Jensen Huang says

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Jeremy Greenwood denies giving ‘ridiculous’ evidence to Icac about ‘mum’s perspective’ from premier’s sister-in-law | Independent Commission Against Corruption
    • Vertrauensfrage à la Merz – POLITICO
    • We don’t need AI regulation — leave safety to us, Nvidia’s Jensen Huang says
    • Acronis warns of actively exploited flaw in its cPanel backup plugin
    • Crypto Turns to Regulators After CLARITY Setback
    • Pushback Mounts Against Trump’s Attacks on the Endangered Species Act
    • NATO Intercepts Suspected Russian Drone in Lithuania
    • Alice Springs heavy metal music venue raises $1m in donations in fight to stay open | Australian music
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Acronis warns of actively exploited flaw in its cPanel backup plugin

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.

    cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces.

    Acronis’ backup add-ons connect the hosting control panel to the company’s infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces.

    The flaw was published in a brief advisory last weekend, but the technology company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8.

    A low-privileged attacker can exploit CVE-2026-87886 to increase their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction.

    Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information.

    Acronis says it has detected exploitation of the vulnerability in the wild, “in limited, targeted attacks.”

    “Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns.

    In a statement for BleepingComputer, Acronis notes that the assessment is based on a single report from a “potentially affected” customer.

    The CVE-2026-87886 vulnerability affects the following product versions:

    • Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021, fixed in version 1.9.3 HF3
    • Acronis Backup extension for Plesk builds earlier than 1.8.11.638, fixed in version 1.8.11

    The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory.

    All affected users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Acronis actively backup cPanel Exploited Flaw Plugin warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Exein Secures $270M at $1.7B Valuation for Physical AI Security

    Coinbase-Backed Crypto Group Warns of Midterms Payback After Clarity Act Fails

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    “We Think the Security Control Is Working” Is No Longer Good Enough

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Jeremy Greenwood denies giving ‘ridiculous’ evidence to Icac about ‘mum’s perspective’ from premier’s sister-in-law | Independent Commission Against Corruption

    September 16, 2026

    Vertrauensfrage à la Merz – POLITICO

    September 16, 2026

    We don’t need AI regulation — leave safety to us, Nvidia’s Jensen Huang says

    September 16, 2026

    Acronis warns of actively exploited flaw in its cPanel backup plugin

    September 16, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Jeremy Greenwood denies giving ‘ridiculous’ evidence to Icac about ‘mum’s perspective’ from premier’s sister-in-law | Independent Commission Against Corruption

    September 16, 2026

    Vertrauensfrage à la Merz – POLITICO

    September 16, 2026

    We don’t need AI regulation — leave safety to us, Nvidia’s Jensen Huang says

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.