Skip to main content
Threat Intelligence · September 19, 2026

Acronis Backup Plugin Under Active Exploitation: What CVE-2026-87886 Means for Your Hosting Stack

A privilege-escalation flaw in Acronis's cPanel/WHM backup plugin is under active exploitation, added to CISA's KEV catalog, and patched with no published IOCs, which means patch status alone won't tell you if a server was already touched.

Vijilan· 8 min read
Acronis Backup Plugin Under Active Exploitation: What CVE-2026-87886 Means for Your Hosting Stack

The News

Acronis's Backup plugin for cPanel and WHM, and reportedly Plesk environments as well, has a local privilege-escalation vulnerability tracked as CVE-2026-87886, and it is being actively exploited in targeted attacks right now. The root cause, per Acronis's own advisory (SEC-10986), is insecure file permissions, the kind of issue that sounds boring on paper and is deeply not boring the moment someone with limited access uses it to become root on a hosting server. Acronis shipped a patch. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog days later. Multiple outlets, from Help Net Security to Bleeping Computer to SC Media, are reporting active exploitation in the wild, not theoretical risk.

If you run cPanel/WHM or Plesk servers for clients, or your MSP or hosting partner does, this affects you. And if you're white-labeling backup infrastructure across a book of hosting clients, this is exactly the kind of vulnerability that hides in plain sight until someone checks.

What CVE-2026-87886 Actually Is

Strip away the CVE number and this is a permissions bug. The Acronis Backup plugin, installed to give backup functionality inside cPanel/WHM control panels, left files with permissions loose enough that a local, low-privileged user could leverage them to escalate to a higher-privileged account, potentially root, on the underlying server. That's the pattern behind most local privilege-escalation flaws: not a clever exploit chain, just a door somebody forgot to lock.

The part that matters for hosting and backup infrastructure specifically is what root access on a cPanel/WHM box actually gets an attacker. These aren't isolated single-tenant machines. They're control panels sitting on top of shared or reseller hosting environments, often running dozens or hundreds of client sites and mailboxes. A privilege escalation on the control panel layer isn't a contained incident, it's a foothold with a blast radius that scales with however many accounts that WHM instance manages.

Who's Affected

Anyone running the Acronis Backup plugin on cPanel/WHM, and per some reporting, Plesk deployments, with a version predating the patch. For MSPs and hosting resellers, the honest answer to "are we affected" starts with an inventory question most teams can't answer instantly: which of our client-facing or white-labeled hosting servers have this plugin installed, and on which version. If backup tooling was rolled out server-by-server over a few years by different techs, that inventory gap is the real exposure, not the CVE itself.

Timeline

Active exploitation and the initial disclosures landed within the same week, with Acronis publishing SEC-10986 and issuing a patch, and CISA adding the vulnerability to its Known Exploited Vulnerabilities catalog shortly after. That's a compressed window between "this is being exploited" and "here's the fix," which is good news for remediation speed and bad news for anyone who was already targeted before the patch existed.

Why Patch Status Alone Doesn't Close This Out

Here's the part that should bother every MSP running white-labeled backup across a hosting fleet: Acronis's advisory doesn't publish indicators of compromise, and there's no public accounting of what attackers who exploited this vulnerability before the patch actually did once they had elevated privileges. Patching stops the door from opening again. It does not tell you whether the door was already used.

That's not a knock on Acronis's disclosure, it's just the normal shape of a privilege-escalation advisory: the vendor's job is to close the hole, not to reverse-engineer every exploitation attempt against every customer. But it leaves a gap that a patch-and-move-on posture cannot fill. If a server was compromised during the exploitation window, the escalation itself was the loud part. What the attacker did with root access afterward, new accounts, modified cron jobs, altered backup schedules, quiet persistence mechanisms, is the quiet part, and quiet is the part detection has to catch, because no advisory is going to hand it to you.

What a Partner Should Actually Do

First, patch. This isn't optional and it isn't a maybe-next-sprint item given active exploitation and KEV inclusion. Second, and more important for anyone who cares about what happened before the patch went in, inventory every hosting or reseller server under your management that has the Acronis Backup plugin installed, across every client, including the white-labeled deployments a junior tech set up two years ago and nobody's touched since. Third, treat any server that ran a vulnerable version before the patch date as a server that needs a look, not just a patch. Privilege escalation that already happened doesn't get undone by a version bump.

Fourth, and this is the part that separates teams that get ahead of this from teams that find out the hard way: stop relying solely on patch cadence as your control for privilege-escalation risk. Patch status tells you whether the door is currently locked. It says nothing about who already walked through it.

Where the Global SOC Comes In

This is precisely the blind spot managed detection exists to cover. Acronis's advisory gives you a fix, not forensics. There are no IOCs to hunt for, no known malicious hash to block, no signature to match. What there is, on any server where this plugin sat unpatched, is a behavioral signal: an account escalating privileges it shouldn't have, a process spawning with permissions inconsistent with its normal baseline, activity on a hosting control panel that doesn't match the pattern of the account that triggered it.

Our Global SOC watches for exactly that class of anomaly, privilege escalation and unusual process behavior on servers, independent of whether the specific exploit has a name yet. ThreatRespond™, our Managed XDR service, correlates endpoint and identity signal to flag privilege changes that don't fit an account's normal role, the kind of activity a vulnerability like CVE-2026-87886 produces whether or not anyone's published IOCs for it. For MSPs and hosting resellers running white-labeled backup across a fleet of client servers, that means the detection isn't dependent on you knowing which specific plugin version each of your two hundred client servers is running on a given Tuesday. It's dependent on whether something on that box started behaving like it shouldn't.

Patch status answers "are we protected going forward." Behavioral monitoring is the only honest answer to "did anything already happen." Relying on the first question alone, across every white-labeled backup deployment in your fleet, is how a permissions bug in a backup plugin turns into the incident nobody noticed until a client asked why their hosting bill looked strange.

We never compete with our partners for their clients. If you're an MSP or hosting reseller trying to figure out what's actually running across your client fleet and whether anything's already moved past the patch line, that's a conversation worth having before the next advisory lands, not after.

See how ThreatRespond™ fits your stack at /msp, or check current plans at /pricing.

Frequently asked questions

What is CVE-2026-87886?

It's a local privilege-escalation vulnerability in the Acronis Backup plugin for cPanel and WHM, caused by insecure file permissions, that allows a low-privileged local user to escalate to a higher-privileged account. It's being actively exploited in targeted attacks and has been added to CISA's Known Exploited Vulnerabilities catalog.

Does patching CVE-2026-87886 undo any damage from prior exploitation?

No. Patching closes the vulnerability going forward but does not reverse or reveal what happened if the flaw was exploited before the patch was applied. Acronis's advisory doesn't publish indicators of compromise, so there's no signature-based way to confirm whether a given server was already targeted.

Does this affect Plesk environments too?

Reporting on this vulnerability has referenced both cPanel/WHM and Plesk deployments of the Acronis Backup plugin. Any hosting or reseller server running the plugin should be checked against the patched version regardless of control panel.

How does a Global SOC help with a vulnerability that has no published IOCs?

Detection built around behavioral anomalies, such as unexpected privilege escalation or process activity inconsistent with an account's normal role, doesn't depend on a vendor publishing specific indicators. ThreatRespond™ correlates endpoint and identity signal to flag that kind of activity whether or not the underlying exploit has a name yet.

Found this useful? Send it to someone who needs it.

Talk to a security expert

See what 24/7 looks like when the SOC actually acts.

Book a 20-minute platform walkthrough: no slide deck, just the console.

Book a walkthrough →