Acronis has confirmed that a high-severity vulnerability in its cPanel backup plugin, also sold for WebHost Manager and Plesk, is being actively exploited.
What the cPanel backup plugin flaw does
The bug is tracked as CVE-2026-87886 and carries a CVSS score of 7.8. Acronis classes it as a local privilege escalation issue caused by insecure file permissions in the Linux build of the Backup plugin, which ships for cPanel and WHM deployments as well as Plesk. In practice that means the plugin leaves a file or directory accessible in a way an unprivileged local account should never be able to reach. An attacker who already has some shell access to the server, through a compromised hosting account, a stolen SSH credential, or a separate initial-access bug, can use that gap to escalate straight to root. The full advisory sits in Acronis’s CVE entry.
This class of bug typically comes from a maintenance or backup routine that runs as root but reads from, or writes to, a location an ordinary user can also touch, letting that user plant something root will later execute. It is not a remote hole on its own, an attacker still needs a foothold first, but on a cPanel or WHM box that foothold is often trivial: any one of the reseller accounts, client sites or support logins already sitting on the same server counts.
That is what makes this flaw worse than an ordinary local bug. A vulnerability that lets any single tenant jump to root turns every account on the box into a potential attack path, not just the ones running vulnerable code themselves.
There is a second angle specific to backup software. A plugin like this already needs broad read access across the filesystem and holds the credentials for wherever backups are shipped, whether that is local storage, an FTP target or a cloud bucket. Root access gained through it is not just privilege escalation on the box, it is a direct route to whatever those backup credentials can reach. That is a bigger prize for an intruder than root on a single web server would be on its own.
Why this fits a pattern
Acronis has not published exploitation details or a count of affected servers, but a flaw hit before most administrators have patched puts this alongside a run of infrastructure software being attacked the same way this month. Teqpost covered Cisco’s Secure Email Gateway zero-day, exploited before a patch existed, on 15 September. The mechanics differ: that bug allowed unauthenticated remote code execution on an email gateway, while the Acronis flaw needs an attacker already on the box before it does anything. The pattern is the same, though. Hosting and backup software that most admins treat as background infrastructure is being probed and hit before disclosure, not after.
What to watch next
Acronis has not said how many servers have been affected or published indicators of compromise, so anyone running the Backup plugin for cPanel, WHM or Plesk on Linux should update to the patched build rather than wait for more detail to surface. Given that exploitation is already active, the priority is closing the local privilege escalation path first and auditing for any root access already gained second, particularly on shared hosting boxes where the exposure was highest to begin with. Acronis has not published a fixed version number in its public statements, so administrators should confirm the patch level directly through their hosting control panel rather than assume an automatic update has already applied it.








