SPOJENO PŘES CVE KEV ✓ EPSS 0.00
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
Acronis cPanel Plesk WebHost Manager FI IT US
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-87886 | 7.8 3.0 · Acronis | KEV ✓ | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 7.8.
Jak se o tom psalo 4
-
· NCSC-FI FI
Acronis - Local privilege escalation due to insecure file permissions
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 7.8, CVEs: CVE-2026-87886, Summary: Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. Affected products Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 Acronis Backup extension for Plesk (Linux) before build 1.8.11.638
-
· CSIRT Itálie (ACN) IT
Acronis: rilevato sfruttamento in rete della CVE-2026-87886
Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-87886 – già sanata dal vendor – che interessa i plugin di backup Acronis per Plesk, cPanel e WHM. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di elevare i propri privilegi sui sistemi interessati.
-
· CISA KEV US
Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886)
CISA added CVE-2026-87886 to the Known Exploited Vulnerabilities catalog. Affected product: Acronis Backup. Remediation due date: 2026-09-19.
-
· BleepingComputer US nadpis události
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]