Cybersecurity 5 min read

A 7.8 Flaw in Acronis Backup Plugins Is Being Exploited Now

Local privilege escalation rarely alarms anyone. On shared hosting, where every customer already has a low-privileged account, it is the whole game.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 18 Sep 2026, 11:12 PM (SGT)
Share:
Patch cables plugged into the numbered ports of a sixteen-port network switch, its link and activity indicators lit Patch cables plugged into the numbered ports of a sixteen-port network switch, its link and activity indicators lit Photo by Bru-nO on Pixabay
Advertisement

18 SEP 2026 — Federal agencies in the United States have until 19 September to patch a flaw in Acronis backup software that attackers are already using.

CVE-2026-87886 scores 7.8, which is modest by the standards of the catalogue it has just entered. It is there because someone is exploiting it, not because of the number.

What the flaw is

The flaw is insecure default file permissions in Acronis Backup integrations for hosting control panels on Linux. An attacker who already has a low-privileged account on the machine can use those permissions to escalate, run arbitrary code and compromise confidentiality and integrity.

Two integrations are affected: the Acronis Backup plugin for cPanel and WHM on Linux before build 1.9.3.1021, fixed in 1.9.3 HF3, and the extension for Plesk on Linux before build 1.8.11.638.

Acronis told customers the update "contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users." Asked for more, a spokesperson said they had nothing to add at this stage.

Why a 7.8 gets a deadline

Local privilege escalation usually does not set off alarms. It assumes the attacker is already on the box, so it looks like a second-stage problem rather than an entry point.

On shared hosting, that assumption does not hold. A low-privileged account is the product being sold. Every customer on the machine has one, and the model depends on those boundaries holding. A flaw that turns any tenant into root needs no remote vector, because the vendor has already sold thousands of people a foothold.

It is the same shape as the Plesk backup manager race condition and the cPanel EmailTrack flaw we covered earlier this month. That is three in three weeks, all in the layer bolted onto the control panel rather than the panel itself.

7.8CVSS, modest for a KEV entry
19 SepFederal remediation deadline
2Control panels affected
LimitedScale of observed exploitation

What is known about the attacks

Very little is known, and the wording is precise about it. Exploitation has been "detected in the wild in limited, targeted attacks." No actor is named, no victim is named, and no date is given for when it started.

"Limited" and "targeted" together usually describe an espionage operation or a crew working a specific customer list, not someone scanning the internet. Neither reading is confirmed, and the absence of detail this week means nothing either way. Attribution on this class of flaw normally arrives later, from whoever handles the incident response.

Where the backup layer sits

Backup software is an attractive target because of the files it must be able to read. A backup agent that cannot reach every customer's files is not doing its job, so it runs with the privileges an attacker wants, on the machine holding the data an attacker wants.

The plugin architecture makes this worse. Hosting providers install these integrations to add backup to a panel that did not ship with it. The panel and the plugin are then maintained by different vendors on different release cycles. The customer sees one system.

Advertisement

What to watch

The deadline is the near-term marker. CISA's catalogue entry, filed under "Acronis Backup Incorrect Default Permissions Vulnerability", was added on 16 September and requires federal agencies to apply vendor mitigations by 19 September under binding operational directive 26-04, or stop using the software. That is three days, short even for a catalogue built for urgency, and the interval is the agency's judgement of how quickly this one matters.

Whether hosting providers patch is the harder question, and federal deadlines do not reach them. The population running these plugins is largely small providers and resellers without a security team, which is the same population that made the Plesk and cPanel flaws worth exploiting.

Three control-panel integrations exploited inside a month is either coincidence or a sign that someone has decided this class of target deserves systematic attention. A fourth arrival, and its speed, would separate the two readings.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement