hacker-news · Crawled Sep 16, 2026
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Read original article ↗AI Summary
A high-severity vulnerability, CVE-2026-87886, in the Acronis Backup plugin for cPanel & WHM and Plesk has been exploited in limited, targeted attacks. The flaw allows local privilege escalation due to insecure file permissions, enabling low-privileged attackers to escalate privileges and execute arbitrary code on affected Linux systems. Acronis has released patches, urging all users to update immediately, though details about the attackers or their objectives remain unknown.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.