Find notable cyber news and cases, enriched with sources, timelines, and signals.

Acronis Backup plugin for cPanel & WHM and Plesk local privilege escalation (CVE-2026-87886)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Acronis Backup plugin deployments for cPanel & WHM and Plesk are affected by CVE-2026-87886, a high-severity Linux local privilege escalation flaw. The vulnerability can let a low-privileged attacker raise permissions on a vulnerable server and put data, websites, and hosting accounts at risk. Acronis says exploitation has been seen in limited, targeted attacks and urges administrators to apply the available updates immediately.

Related Happenings

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

CPanel CVE-2026-41940 mitigation guidance

Advisory/Mitigation
H score89 First: 30.04.2026 14:40 Last: 30.04.2026 14:40 Sources 1

About this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

CISA updates KEV entry for CVE-2026-1731

Public Sector Action
H score36 First: 20.02.2026 17:45 Last: 20.02.2026 17:45 Sources 1

About this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...

Timeline

  1. 16.09.2026 00:37 2 articles · 1h ago

    Acronis warns of active exploitation in backup plugins for cPanel & WHM and Plesk

    Initial Disclosure

    On 2026-09-15, Acronis identified CVE-2026-87886, a high-severity Linux local privilege escalation flaw in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. The vulnerability can let a low-privileged attacker raise permissions on a vulnerable Linux server, and Acronis said exploitation has been detected in limited, targeted attacks. The company urged administrators to apply the available updates for cPanel & WHM builds earlier than 1.9.3.1021 and Plesk builds earlier than 1.8.11.638.

    Show sources