Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities SecurityWeek

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

A high-severity insecure file permissions flaw (CVE-2026-87886, CVSS 7.8) in the Acronis Backup plugin for cPanel & WHM allows local privilege escalation and has been exploited in targeted attacks. Affected versions are all Linux builds of the plugin before 1.9.3.1021 and the Backup extension for Plesk before 1.8.11.638. Acronis urges users to update their deployments immediately to the patched builds, though no specific workarounds are provided in the advisory.
Read Full Article →

Vulnerabilities Acronis Patches Exploited Vulnerability in cPanel Backup Plugin CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation. By Ionut Arghire | September 16, 2026 (5:52 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Acronis on Tuesday rolled out urgent patches for a vulnerability in the Backup plugin for cPanel & WHM that has been exploited in the wild. The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments. Insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges. The vulnerability is tracked as CVE-2026-87886 (CVSS score of 7.8) and has been exploited in the wild against the plugin, but not against the extension. “Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory . The company says all Linux versions of the Backup plugin for cPanel & WHM before build 1.9.3.1021 and the Backup extension for Plesk before build 1.8.11.638 are affected. Advertisement. Scroll to continue reading. Acronis has not shared technical details on the vulnerability but urges users to update their deployments immediately. Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Related: Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire 240,000 Hit by Data Breach at Japan’s Digital Agency Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Personal, Financial Info Exposed in Revolut Data Breach Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Three JFrog Artifactory Flaws Exploited for Backdoor Deployment ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days Latest News Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? “We Think the Security Control Is Working” Is No Longer Good Enough $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws Exein Secures $270M at $1.7B Valuation for Physical AI Security Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data Thai Broadband Provider Hacked via Fortinet Vulnerability Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the Move Geoff Belknap has joined HubSpot as Chief Trust Officer. Zero Networks has named Yossi Dagan as Chief Financial Officer. Manifold has appointed Joe Sullivan to its Board of Directors. More People On The Move Expert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Share this article