CVE-2026-87886
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Coverage 1 source
-
2026-09-16
Help Net Security
high
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
Acronis backup plugin vulnerability CVE-2026-87886 is being exploited in targeted attacks.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands