Skip to content
Rush Commerce
Software & Dev3 min read

Acronis cPanel backup plugin exploited: patch your host

Acronis says a privilege-escalation flaw in its cPanel, WHM and Plesk backup plugins is exploited in the wild. Fixed builds, and what to ask your hosting provider.

The Acronis backup plugin for cPanel is the kind of software nobody on your team installed and nobody on your team tracks — your host did, and it runs as root-adjacent on the box holding your site. Acronis disclosed a high-severity Linux privilege-escalation flaw in it on September 15 and says exploitation has been seen in the wild. If you are on shared or managed hosting, this is a vendor question you have to go ask, because you cannot patch it yourself.

What actually happened

BleepingComputer reports the flaw as CVE-2026-87886, rated CVSS 7.8. A low-privileged local attacker can escalate on the server — read or modify data, disrupt the system — with no user interaction required.

Affected and fixed builds:

  • Acronis Backup plugin for cPanel & WHM: builds before 1.9.3.1021; fixed in 1.9.3 HF3
  • Acronis Backup extension for Plesk: builds before 1.8.11.638; fixed in 1.8.11

Acronis says exploitation was detected "in limited, targeted attacks," and BleepingComputer notes that assessment rests on a single customer report. Full technical details were held back to give administrators a window to patch. Acronis publishes fixes through its security advisory database.

Why this matters for your business

A local escalation on shared hosting is not a local problem. The "low-privileged attacker" here is whoever already has a foothold on the box — a neighbor account on the same shared server, a compromised FTP login, a web shell dropped through somebody else's outdated plugin. On a machine where one root escalation reaches every site in the rack, "local" is a very short walk. We wrote about the same shape when a cPanel flaw let one neighbor account reach root.

Send your host one email today. Ask three things: which Acronis plugin build is running, when it will be patched to 1.9.3 HF3 or 1.8.11, and whether they have checked for exploitation on servers hosting your account. A managed host that cannot answer within a business day is telling you something about the rest of their patch cadence. Put the reply in writing.

Your backups are the thing being attacked. The vulnerable component is the backup agent. Whatever it can reach, an attacker with root on that host can reach too — including the snapshot you would restore from. Keep at least one copy of your site and database somewhere your host does not control, and confirm it restores. A backup you have never restored is a hypothesis.

Inventory the software you did not install. Control panel plugins, backup agents, monitoring daemons, mail filters. None of it appears in your repo, none of it shows up in your dependency scan, and all of it runs next to your data. Write the list down once. It is short, and it is the list you will need the next time an advisory lands.

Key takeaways

  • CVE-2026-87886, CVSS 7.8: privilege escalation in Acronis backup plugins for cPanel/WHM and Plesk
  • Acronis reports exploitation in the wild in limited, targeted attacks
  • Fixed in cPanel & WHM build 1.9.3 HF3 and Plesk build 1.8.11 — patch immediately
  • On shared hosting you cannot patch this; ask your provider for the build number and a patch date in writing
  • The vulnerable component is the backup agent, so keep one restore-tested copy off your host
  • Inventory the control-panel software you never installed — it runs next to your data

Not sure what is running under your site? We audit the hosting layer, set up off-host backups we actually restore in front of you, and write the vendor questions you should be asking. See what that covers or book a hosting review.

Sources: BleepingComputer, Acronis Security Advisory Database.

  • #acronis
  • #cpanel
  • #privilege-escalation
  • #web-hosting
  • #patching
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.