Keypoints
- Acronis disclosed CVE-2026-87886 in its backup plugin for cPanel & WHM and Plesk.
- The flaw is a Linux local privilege escalation issue with a CVSS score of 7.8.
- A low-privileged attacker could use it to gain higher permissions on a vulnerable server.
- Acronis says the vulnerability has been exploited in limited, targeted attacks.
- Users should update Acronis Backup plugin for cPanel & WHM and Acronis Backup extension for Plesk immediately.