Acronis Issues Urgent Security Update for Backup Extensions Following Active Attacks

Acronis has issued an urgent warning regarding a high-severity local privilege escalation (LPE) vulnerability in its backup plugins for cPanel, WHM, and Plesk. The flaw, tracked as CVE-2026-87886, is reportedly being exploited in the wild through limited, targeted attacks against Linux-based hosting environments.

The vulnerability carries a CVSS severity score of 7.8 and allows a low-privileged attacker to escalate their permissions to the system level. Because this exploit requires no user interaction, it poses a significant risk to shared hosting providers, where a single compromised or malicious customer account could potentially be used to gain full control over the entire server infrastructure.

A cracking digital shield protecting a backup icon.
The vulnerability allows attackers to escalate privileges within Linux-based hosting environments.

Affected Versions and Patch Requirements

The security flaw resides in the way the Acronis backup agent interacts with the Linux hosting control panels. Acronis has confirmed that the vulnerability is being exploited in the wild in limited, targeted attacks.

Administrators managing web hosting servers should verify their current plugin versions immediately. The following builds are identified as vulnerable:

  • Acronis Backup plugin for cPanel & WHM: All builds earlier than 1.9.3.1021.
  • Acronis Backup extension for Plesk: All builds earlier than 1.8.11.638.

To mitigate the risk, hosting providers must update to version 1.9.3 HF3 for cPanel/WHM deployments and version 1.8.11 for Plesk environments. Acronis has not indicated that Windows-based versions of the agent are affected by this specific LPE vulnerability.

Limited Forensic Visibility

Acronis is currently withholding specific technical details and Indicators of Compromise (IoCs) to prevent other threat actors from developing functional exploits while administrators work to apply patches. While this prevents a surge in automated attacks, it also leaves IT departments with limited options for retroactive forensic audits.

In the absence of specific IoCs, security teams are advised to prioritize the update over manual investigation. The primary risk remains the transition from a “web user” or “customer” permission level to “root” access, which could allow an attacker to bypass data isolation, access other customers’ files, or disable backup routines entirely.

Hosting providers are encouraged to enable automatic updates for their control panel extensions where possible to ensure that future hotfixes are applied without delay. For environments where manual approval is required, the 1.9.3 HF3 and 1.8.11 updates should be treated as critical security maintenance.

More From Category

More Stories Today