Acronis warns that a Linux local privilege escalation vulnerability in its backup plugin for hosting panels is being exploited in limited, targeted attacks. The issue is tracked as CVE-2026-87886 and affects Acronis Backup extensions for cPanel and WebHost Manager (WHM), with the company assessing whether exploitation is occurring in other environments.

SecurityWeek and Bleeping Computer describe the vulnerability as a high-severity insecure file permissions problem that can allow local privilege escalation. They report that Acronis has issued patches to address the flaw and that exploitation activity has been observed in the wild. Help Net Security adds that, at the time of reporting, there are no signs of active exploitation in Plesk deployments.

Across outlets, the main differences are emphasis and scope: some focus on the technical severity and risk of local privilege escalation, while others stress Acronis’ statement about limited, targeted attacks and the panel-specific observations regarding cPanel/WHM versus Plesk. All accounts point to the same CVE and the need to apply the vendor’s fixes.