Acronis’ advisory says exploitation has been detected in “limited, targeted attacks” against deployments of the Acronis Backup plugin for cPanel & WHM. BleepingComputer, which first reported the CVE assignment and score on September 15, says Acronis based that assessment on a single report from a potentially affected customer. That is enough to justify urgent patching, but it is not the same as evidence of broad, automated exploitation across hosting providers.
The reporting and Acronis’ public records establish a narrower, more useful conclusion for server operators: the flaw is a local elevation-of-privilege issue, not a newly disclosed remote login bypass in cPanel itself. A hostile user or process first needs some level of access on a vulnerable Linux server. On shared-hosting systems, that distinction still deserves attention because an ordinary hosting account, compromised application, stolen customer credential, or existing malware foothold can provide the starting point an attacker needs.
The Exploitation Claim Applies to cPanel & WHM Deployments
Acronis lists both its cPanel & WHM plugin and Plesk extension as affected by CVE-2026-87886. Yet its public exploitation language specifically identifies “Acronis Backup plugin for cPanel & WHM deployments,” rather than Plesk installations. BleepingComputer likewise reports that Acronis has not disclosed evidence of Plesk exploitation.
That does not make Plesk safe to defer. It means defenders should avoid overstating the record: the vulnerability spans both integrations, while the observed activity Acronis describes is tied to the cPanel & WHM product. Plesk estate owners should update as part of the same emergency maintenance work, but incident-response teams should give initial hunting priority to cPanel & WHM servers using the Acronis integration.
Acronis has not released indicators of compromise, a detailed attack chain, victim sectors, or a timeframe for the reported activity. The company also has not said whether the potentially affected customer was compromised successfully, what access the attacker held before escalation, or whether the activity involved a managed hosting provider. Those omissions leave administrators without a reliable way to declare an unpatched server clean merely because they cannot find a published signature.
For now, the defensible assumption is that a vulnerable cPanel server with any suspicious local-access event deserves review after patching. That includes unexpected privileged processes, changes under Acronis plugin directories, unfamiliar scheduled tasks, new SSH keys, modified account ownership, and anomalous access to backup archives or restoration activity. These are general post-compromise checks rather than Acronis-specific indicators; Acronis has published none.
The Patch Version Is More Specific Than “Update to 1.9.3”
The exact fixed thresholds matter. According to Acronis and the details reported by BleepingComputer, the affected ranges are:
- Acronis Backup plugin for cPanel & WHM is affected before build 1.9.3.1021 and fixed in version 1.9.3 HF3.
- Acronis Backup extension for Plesk is affected before build 1.8.11.638 and fixed in version 1.8.11.
This is not a case where simply seeing “1.9.3” in an inventory report should end the investigation. Acronis had already issued earlier 1.9.3 hotfix builds before the security fix. Its release notes identify build 998 as 1.9.3 HF2 and build 1021 as 1.9.3 HF3. A host on 1.9.3 build 998 remains below the fixed cPanel threshold.
The Plesk side has the same operational pitfall in a different form. Acronis’ release notes identify 1.8.11 as build 638, so organizations should record and validate the build number, not only the marketing version. This is particularly relevant for hosting fleets where extensions are deployed through templates, automation systems, or provider-managed update channels that can leave servers at different hotfix levels.
Acronis’ advisories were initially sparse: the cPanel & WHM update appeared before the company published the CVE identifier, technical classification, affected-version ranges, and CVSS score. That staged disclosure is common when a patch is available but active exploitation is suspected. It also means asset owners who treated the September 11 security release as routine maintenance may have missed its urgency before the fuller advisory appeared on September 15.
Version 1.9.4 Introduces a Deployment Decision
Acronis released cPanel & WHM plugin version 1.9.4 build 1022 on September 11, the same date its release notes list build 1021, the patched 1.9.3 HF3 release. Version 1.9.4 adds support and product changes, including two-factor-authentication workflow support, Ubuntu 22.04 LTS validation, AlmaLinux 10 and cPanel version 132 validation, and backup browsing from S3-compatible storage.
However, the two releases have different stated prerequisites. Build 1021 requires Acronis Cyber Cloud and the protection agent at version C26.02, while build 1022 requires them at version C26.08. That makes version 1.9.4 a sensible destination for organizations already aligned with the newer Acronis platform release, but it may not be the fastest emergency path for every production host.
For a cPanel server that cannot immediately move its Acronis Cyber Cloud components and protection agent to C26.08, build 1.9.3.1021 is the documented minimum fixed version. Administrators should not delay remediation while planning an upgrade to 1.9.4 if the lower fixed hotfix is compatible with their current environment.
Conversely, teams that do choose 1.9.4 should validate more than the plugin package installation. The backend dependency means change records should include the protection-agent version and Acronis Cyber Cloud version, plus a post-update test of the operations that matter in that environment: backup visibility, scheduled jobs, account-level restores, database recovery, and access to existing recovery points. A security update that disconnects a hosting control panel from its backups can create a different outage during the same maintenance window.
What Hosting Administrators Should Do Tonight
The first task is to identify whether the Acronis control-panel integration is installed at all. A cPanel or Plesk server without the Acronis plugin or extension is outside the product scope of CVE-2026-87886. This is an Acronis integration issue, not a blanket advisory affecting every cPanel, WHM, or Plesk installation.
For affected servers, administrators should inventory the exact plugin or extension build, apply the fixed release or a later compatible release, and retain evidence of the installed version. Shared hosting providers should check every server image and automation path, rather than assuming the version on one control-plane node represents the fleet.
After patching, focus review on systems with plausible initial access: servers hosting compromised sites, accounts with recent credential resets, systems where customers can upload or execute code, and hosts that show unexplained privilege or ownership changes. Because Acronis has not supplied indicators of compromise, patching removes the known escalation route but does not prove that an earlier local compromise did not use it.
The concrete deadline is now. Acronis has acknowledged targeted exploitation, the cPanel & WHM plugin has a fixed build with a lower platform requirement than the newer feature release, and the Plesk extension has its own fixed build. Organizations running these backup integrations should treat the issue as a version-control and fleet-verification job—not wait for exploit code or a published detection signature before closing the hole.