Security & Risk5 minNewsroom

Acronis Patches CVE-2026-87886 After Exploitation; 72h Warning

Sala de servidores com um técnico solitário trabalhando em correção emergencial durante a madrugada.

A privilege escalation flaw in Acronis backup plugins has been exploited in limited attacks, sparking a U.S. government patch mandate.

Acronis has released an emergency patch for CVE-2026-87886, a local privilege escalation vulnerability in its backup plugins for cPanel & WHM and Plesk panels on Linux, following detection of exploitation in targeted attacks. The CISA, the U.S. government's cybersecurity agency, added the vulnerability to its catalog of actively exploited vulnerabilities (KEV) on September 16, with a remediation deadline of September 19 for civilian federal agencies: 72 hours.


The flaw rates 7.8 on the CVSS scale. Its source appears trivial yet is devastating in practice: misconfigured file permissions in the directory where the backup plugin operates. A local user with low privileges, like a common account on a shared server, can escalate to root and take control of the entire machine. No victim interaction is needed, no obvious alerts are triggered, and no trace is left outside of system logs. The patched versions of the plugin for cPanel are 1.9.3 HF3 and later than 1.9.3.1021; the Plesk add-on also received a patch, although Acronis states it has not observed any exploitation on Plesk.


Why This Bug Matters More Than Its CVSS Score Indicates


The real severity stems from the shared hosting business model. A single cPanel server hosts dozens to hundreds of clients, each with their own isolated Linux account. Backups run with elevated permissions because they need to read data from all accounts. When the plugin orchestrating these backups leaves a window open for escalation, any tenant in the building gains the master key: they can read a neighbor's database, plant shells in other accounts, compromise the TLS certificate of the entire server. This is not a breach in a company; it’s a breach in a market layer.


CISA has been explicit in alleging exploitation in the real world. According to the agency, the KEV only includes vulnerabilities when there is concrete evidence of use in attacks, not just proof of concept. Acronis, in turn, confirmed that the observed exploitation is limited and targeted, with no signs of mass campaigning. This usually indicates an operator with a specific objective, target recognition, and not an access broker selling on forums.


Where the Exposure Really Lies


The cPanel toolset is the backbone of the global shared hosting market, from independent resellers to medium-sized operators. In the United States, providers like GoDaddy and Bluehost maintain huge parks of cPanel servers. In India, hosting hubs in Bengaluru and Mumbai serve global clients with thin margins and not always aggressive patch cycles. In Europe, German and French SMB providers rely on the cPanel and Acronis combo to serve small law offices, accounting firms, and medical practices subject to GDPR. Each of these markets inherits the risk of this CVE.


The Brazilian scenario repeats this topology, with resellers serving accounting offices, digital notaries, and service providers running WordPress and legacy ERP systems on the same server. For the CISO, the issue is not the company’s own server but the third-party server that hosts the payment integration or vendor portal.


What to Do in the Next 48 Hours


The window until September 19 is tight by design. CISA activates short deadlines when it wants to signal urgency to the private sector without issuing a separate alert. A hosting operator that applies the patch after the deadline inherits an awkward contractual argument if a client demands an explanation, and adds regulatory risk in jurisdictions with mandatory incident reporting. According to Acronis, the hotfix can be applied without significant downtime in most configurations.


Detection teams have a clear roadmap: look for write attempts in the plugin’s directories by users without privileges, compare binary signatures of installed versions against patched ones, and review logs of scheduled system task executions. The lack of public mass exploitation provides space to contain it now. Waiting for the exploit to emerge from private circuits often incurs high costs.


A temporal detail deserves closer reading. Acronis first observed targeted attacks; inclusion in the KEV followed, suggesting coordination between the vendor and CISA regarding the timing of disclosure. This pattern has been repeating in recent flaws in management and backup platforms, signaling that the U.S. agency is narrowing the gap between discreet discovery and public obligations. For security managers, this changes expectations around patch windows: the 72-hour deadline is no longer an exception reserved for critical flaws in federal software and now applies to widely deployed private vendors in the market.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk