# Acronis flags exploited privilege-escalation flaw in backup plugins

_Published Tuesday, September 15, 2026 at 9:07 PM EDT · Security · Latest · Tier 1 — Major_

![Acronis flags exploited privilege-escalation flaw in backup plugins — Primary](https://www.bleepstatic.com/content/hl-images/2024/07/26/Acronis.jpg)

Acronis has identified CVE-2026-87886, a high-severity local privilege-escalation vulnerability in its backup integrations for cPanel, WHM and Plesk. The company says exploitation has been detected in limited, targeted attacks, based on a single report from a potentially affected customer. A low-privileged attacker could raise permissions on a vulnerable Linux server, potentially accessing or changing sensitive data and disrupting the system. Acronis released fixes for affected cPanel and Plesk plugin versions.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/)

---
Canonical: https://techandbusiness.org/newswire/6H_dcWX63haFfiXShRx0Fx
Published: 2026-09-16T01:07:46.986Z
Story chronology: 2026-09-15T21:37:35.000Z
Retrieved: 2026-09-16T02:49:32.408Z
Publisher: Tech & Business (techandbusiness.org)
