Executive Summary
In September 2026, Acronis disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability in its backup plugins for cPanel, WebHost Manager (WHM), and Plesk. The vulnerability allows low-privileged attackers to escalate permissions on vulnerable Linux servers without user interaction, potentially enabling access to sensitive data and system disruption. Acronis confirmed active exploitation in limited, targeted attacks against hosting environments, prompting immediate patching recommendations for affected versions.
This incident highlights the growing trend of attackers targeting web hosting infrastructure and third-party plugins, which provide attractive attack surfaces due to their privileged access to multiple customer environments and critical business operations.
Why This Matters Now
Web hosting infrastructure attacks are increasing as attackers recognize the potential for lateral movement across multiple customer environments through compromised hosting platforms, making privilege escalation vulnerabilities in popular plugins particularly dangerous.
Attack Path Analysis
Attackers exploited CVE-2026-87886, a Linux local privilege escalation vulnerability in Acronis backup plugins for cPanel/WHM and Plesk. Initial compromise likely occurred through web application exploitation or credential abuse to gain low-privileged access. The vulnerability was then exploited to escalate privileges on Linux servers hosting the backup plugins. From elevated privileges, attackers could move laterally to other systems, establish persistent command and control channels, exfiltrate sensitive hosting data including customer information and backups, and potentially disrupt hosting services or deploy ransomware.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained initial low-privileged access to Linux servers running Acronis backup plugins through web application vulnerabilities, credential stuffing, or social engineering targeting hosting administrators
Related CVEs
CVE-2026-87886
CVSS 7.8A local privilege escalation vulnerability in Acronis Backup plugin for cPanel & WHM and Plesk that allows low-privileged attackers to increase their permission level on vulnerable Linux servers.
Affected Products:
Acronis Backup plugin for cPanel & WHM – < 1.9.3.1021
Acronis Backup extension for Plesk – < 1.8.11.638
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Exploit Public-Facing Application
Web Shell
Local Accounts
Process Injection
OS Credential Dumping
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework and Processes
Control ID: 6.2.4
CISA ZTMM 2.0 – Application Asset Management
Control ID: Application Security - AS.AM-01
NYDFS 23 NYCRR 500 – Vulnerability Management
Control ID: 500.08(b)
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)(a)
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Internet
Web hosting providers using cPanel/Plesk with Acronis backup plugins face critical privilege escalation risks, enabling attackers to compromise customer websites and sensitive hosting data through exploited backup integrations.
Information Technology/IT
IT service providers managing Linux servers with affected Acronis backup plugins experience heightened privilege escalation threats, potentially allowing unauthorized access to client infrastructure and critical system modifications without user interaction.
Computer Software/Engineering
Software companies utilizing cPanel/WHM or Plesk for development environments face targeted attacks exploiting CVE-2026-87886, risking source code exposure and development infrastructure compromise through backup plugin vulnerabilities.
Financial Services
Financial institutions using affected backup solutions for web applications face regulatory compliance violations and data breach risks, as privilege escalation attacks could compromise sensitive financial data and customer information systems.
Sources
- Acronis warns of actively exploited flaw in its cPanel backup pluginhttps://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/Verified
- Acronis Security Advisory SEC-10986https://security-advisory.acronis.com/advisories/SEC-10986Verified
- Acronis Update UPD-2609-3d72-20a7https://security-advisory.acronis.com/updates/UPD-2609-3d72-20a7Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this Linux privilege escalation attack by limiting lateral movement across hosting infrastructure and reducing blast radius through workload segmentation. The attack's scope would be diminished even after initial compromise through controlled east-west traffic flows.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial foothold would likely be contained within a segmented hosting environment, reducing their ability to immediately survey the broader infrastructure landscape and limiting reconnaissance of adjacent customer hosting accounts.
Control: Zero Trust Segmentation
Mitigation: While local privilege escalation may still occur on the compromised server, zero trust segmentation would likely limit the scope of elevated access to that specific workload, reducing the attacker's ability to leverage escalated privileges across the hosting infrastructure.
Control: East-West Traffic Security
Mitigation: Lateral movement across hosting servers would likely be significantly constrained, with east-west traffic controls blocking unauthorized server-to-server communications and limiting access to customer databases and hosting accounts based on workload identity.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be detected and constrained through comprehensive traffic visibility, with unauthorized outbound connections from hosting servers potentially blocked or flagged for investigation based on communication patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration would likely be constrained through egress policy enforcement, with large data transfers from hosting servers potentially blocked or rate-limited, reducing the volume of customer data and backup files that could be stolen.
The overall impact would likely be limited to specific hosting servers rather than affecting the entire hosting infrastructure, with customer data exposure constrained to accounts directly hosted on compromised workloads rather than spreading across the platform.
Impact at a Glance
Affected Business Functions
- Web Hosting Services
- Server Management
- Backup and Recovery Operations
- Customer Website Maintenance
Estimated downtime: 2 days
Estimated loss: N/A
Potential access to sensitive customer website data, databases, mailboxes, and hosting account information managed through compromised cPanel and Plesk installations
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate hosting infrastructure and prevent lateral movement between customer environments and administrative systems
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration from hosting servers to external destinations
- • Enable Multicloud Visibility & Control to monitor for anomalous interactions and repeated malformed requests targeting backup plugins and hosting control panels
- • Activate Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads targeting privilege escalation vulnerabilities like CVE-2026-87886
- • Implement Cloud Native Security Fabric (CNSF) with real-time inspection and autonomous response to detect and prevent privilege escalation attempts before they succeed



