Executive Summary
Acronis disclosed that CVE-2026-87886, a high-severity privilege escalation vulnerability in its Backup plugin for cPanel and WHM deployments, has been actively exploited in targeted attacks. The flaw, scoring 7.8 on CVSS, stems from insecure file permissions that allow attackers with low-level access to escalate privileges on vulnerable Linux systems. Successful exploitation enables unauthorized actions and arbitrary code execution, potentially compromising application confidentiality and integrity across web hosting environments.
This incident highlights the growing trend of supply chain vulnerabilities targeting managed hosting infrastructure, where a single compromised plugin can provide attackers with elevated access across multiple customer environments. The active exploitation underscores the critical need for immediate patch management in hosting environments where administrative tools create expanded attack surfaces.
Why This Matters Now
Web hosting infrastructure faces increasing attacks targeting administrative plugins and backup solutions, with privilege escalation vulnerabilities providing attackers persistent access to multi-tenant environments where lateral movement can impact numerous customers simultaneously.
Attack Path Analysis
Attackers exploited CVE-2026-87886, a high-severity privilege escalation vulnerability in Acronis Backup plugin for cPanel/WHM due to insecure file permissions. After gaining initial access with low privileges, attackers escalated to higher permissions and likely moved laterally across managed hosting environments. Command and control was established to maintain persistence, followed by potential data exfiltration and impact to backup integrity and customer data.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained initial access to Linux systems running vulnerable Acronis Backup plugin for cPanel/WHM with low-privilege user accounts, targeting web hosting environments
Related CVEs
CVE-2024-50873
CVSS 7.8A local privilege escalation vulnerability in Acronis Backup plugin for cPanel & WHM due to insecure file permissions allows low-privileged attackers to escalate permissions and execute arbitrary code.
Affected Products:
Acronis Backup plugin for cPanel & WHM – < 1.9.3.1021
Acronis Backup extension for Plesk – < 1.8.11.638
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
File and Directory Permissions Modification: Linux and Mac File and Directory Permissions Modification
Hijack Execution Flow: Services File Permissions Weakness
Valid Accounts: Local Accounts
Scheduled Task/Job: Cron
Command and Scripting Interpreter: Unix Shell
Exploit Public-Facing Application
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Bespoke and Custom Software
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.10
CISA ZTMM 2.0 – Software platforms and applications within the organization are inventoried
Control ID: ID.AM-2
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Separation of development, testing and operational environments
Control ID: A.8.31
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Internet
Web hosting providers using Acronis cPanel backup plugins face critical privilege escalation risks, enabling attackers to compromise customer data and hosting infrastructure through insecure file permissions.
Information Technology/IT
IT service providers managing Linux-based backup systems are vulnerable to local privilege escalation attacks, potentially compromising client environments and requiring immediate patch deployment across managed infrastructure.
Computer Software/Engineering
Software companies utilizing Acronis backup solutions in development environments risk unauthorized code access and intellectual property theft through exploited privilege escalation vulnerabilities in cPanel deployments.
Financial Services
Financial institutions using affected Acronis backup plugins face regulatory compliance violations and data breach risks, as privilege escalation could compromise sensitive customer financial information and transaction systems.
Sources
- Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attackshttps://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.htmlVerified
- Acronis Security Advisory UPD-2609-3d72-20a7https://security-advisory.acronis.com/updates/UPD-2609-3d72-20a7Verified
- Acronis Security Advisory UPD-2609-efb0-50b2https://security-advisory.acronis.com/updates/UPD-2609-efb0-50b2Verified
- CVE-2024-50873 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2024-50873Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be relevant to this Acronis backup plugin attack by constraining lateral movement across hosting infrastructure and reducing the blast radius through workload segmentation. The multi-stage privilege escalation and cross-customer impact could likely be limited through identity-aware access controls and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial access to vulnerable cPanel/WHM systems would likely remain possible, but the scope of reachable resources and workloads could be significantly constrained through cloud-native security fabric controls
Control: Zero Trust Segmentation
Mitigation: While the file permissions vulnerability could still be exploited, zero trust segmentation would likely constrain the scope of elevated privileges and limit access to sensitive backup system components
Control: East-West Traffic Security
Mitigation: Cross-customer lateral movement and infrastructure traversal would likely be significantly constrained, reducing the ability to reach multiple hosting environments from a single compromised system
Control: Multicloud Visibility & Control
Mitigation: Command and control establishment may still occur, but multicloud visibility would likely provide enhanced detection capabilities and constrain the scope of persistent access across distributed hosting environments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely face significant constraints through controlled egress policies, reducing the volume and scope of sensitive backup data that could be extracted
Residual impact would likely be contained to isolated hosting segments rather than affecting the entire shared infrastructure, significantly reducing the scope of backup integrity compromise
Impact at a Glance
Affected Business Functions
- Web Hosting Services
- Backup and Recovery Operations
- Server Administration
- Customer Data Management
Estimated downtime: 2 days
Estimated loss: N/A
Potential exposure of web hosting customer data, backup archives, and server configuration files containing sensitive credentials and application data hosted on affected cPanel/WHM systems
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate backup systems and limit lateral movement across hosting environments
- • Deploy egress security controls to detect and prevent unauthorized data exfiltration from backup repositories
- • Enable multicloud visibility to monitor anomalous access patterns and privilege escalation attempts in hosting infrastructure
- • Apply inline IPS with updated signatures to detect CVE-2026-87886 exploitation attempts and similar privilege escalation attacks
- • Establish encrypted traffic controls and east-west security to protect backup data flows between systems and prevent unauthorized access



