Vulnerability
Published 2026-09-15
Verified 2026-09-19

Acronis Backup plugin for cPanel/WHM and Plesk: Linux LPE CVE-2026-87886 (CVSS 7.8); limited in-the-wild exploitation

Acronis security advisory SEC-10986 / update UPD-2609-3d72-20a7 (wired by BleepingComputer 15 September 2026) covers CVE-2026-87886, a high-severity Linux local privilege escalation in Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Acronis assigns severity 7.8. A low-privileged attacker can raise privileges on a vulnerable Linux host without user interaction; further exploit detail withheld while patches propagate. Acronis says exploitation has been detected in the wild in limited, targeted attacks against cPanel & WHM plugin deployments (assessment based on a single report from a potentially affected customer; no public IoCs released). Affected: cPanel & WHM plugin builds earlier than 1.9.3.1021 (fixed 1.9.3 HF3); Plesk extension builds earlier than 1.8.11.638 (fixed 1.8.11). Apply those updates immediately. Primary: Acronis SEC-10986; wire: BleepingComputer 15 Sep. UPDATE 16 September 2026: CISA added CVE-2026-87886 to KEV (same alert as Cisco ISE CVE-2026-76460). Distinct from desk card cve-2026-60004 (Gitea / Red Heron).

Product
Acronis Backup plugin for cPanel & WHM; Acronis Backup extension for Plesk
Versions
cPanel/WHM plugin < 1.9.3.1021 (fix 1.9.3 HF3); Plesk extension < 1.8.11.638 (fix 1.8.11)
CVSS
7.8
Exploited in Australia?
unknown
Patch to
cPanel/WHM plugin 1.9.3 HF3 (build 1.9.3.1021+); Plesk extension 1.8.11+

Primary: Acronis SEC-10986 — CVE-2026-87886 · Vendor: Acronis update UPD-2609-3d72-20a7 · CVE: CVE-2026-87886, CVE-2026-76460, CVE-2026-60004 · BleepingComputer — Acronis cPanel/Plesk backup plugin LPE (15 Sep 2026)

vulnerabilities cloud