The Acronis backup plugin for cPanel & WHM has a vulnerability that has already been exploited in targeted attacks: an account with limited privileges on the server gains full control on Linux (CVE-2026-87886).
Many small businesses host their websites or online stores on shared hosting, managed through the cPanel & WHM control panel, and use an Acronis plugin to create backups. It is precisely that plugin that contains the CVE-2026-87886 vulnerability, and the vendor confirms that it has already been exploited in limited, targeted attacks.
The technical cause is trivial but dangerous: incorrect file permissions. Because of them, an account with limited privileges on the server can elevate its own privileges to full control over the Linux system. On a shared hosting server, where multiple companies share the same server, a compromised neighboring account can thus gain more access than it should—including to other customers’ files and data.
For a small business, there are two major concerns. On the one hand, there’s the server that keeps your website up and running; on the other, even the backup tool—the one that’s supposed to save you when something goes wrong—becomes the weak link. It’s not something you can fix yourself from your computer: the fix has to be applied on the server by the person who manages it.
What you need to do:
- Ask your hosting provider if the server uses the Acronis backup plugin for cPanel & WHM and if it is updated to version 1.9.3 HF3 (on Plesk: 1.8.11.638 or later).
- Ask for written confirmation that the fix has been applied, not just a vague assurance.
- Keep a copy of your website and database off the hosting server as well, so you can restore them if the server is compromised.
Five minutes with the hosting provider and a separately stored backup close a door that attackers are already trying to break through.
Sources:
This article was generated with AI assistance.