Acronis CVE-2026-87886 is now in the CISA Known Exploited Vulnerabilities catalog, raising the patch priority for hosting environments using affected Acronis Backup integrations with cPanel & WHM or Plesk. This is a local privilege-escalation flaw linked to insecure or incorrect file permissions, not an established unauthenticated remote-code-execution vulnerability.
Which Acronis Backup versions need to be patched?
For Linux systems, current evidence indicates that Acronis Backup for cPanel & WHM should be updated to 1.9.3 HF3 build 1021 or later. Acronis Backup for Plesk should be updated to 1.8.11 build 638 or later.
For cPanel & WHM, checking only the visible version label is not enough: several builds exist under the 1.9.3 family, and the security-fix release is specifically HF3 build 1021.

Why did CISA add CVE-2026-87886 to KEV?
CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on September 16, 2026. KEV inclusion means exploitation is known to have occurred and gives the vulnerability a materially higher operational patch priority than an ordinary unexploited CVE.
The CISA entry lists a September 19 remediation due date for relevant federal assets. That deadline should not be described as a universal legal deadline for every private company. Private hosting providers and enterprises can still use KEV inclusion as a strong risk-based patching signal.
What kind of vulnerability is CVE-2026-87886?
The vulnerability is a local privilege-escalation issue associated with insecure or incorrect default file permissions in affected Acronis Backup control-panel integrations.
Current vendor-attributed reporting describes exploitation by a low-privileged attacker who already has access to the vulnerable Linux system and can then escalate privileges. TPS therefore does not describe CVE-2026-87886 as a direct unauthenticated remote attack from the internet.
That distinction matters on shared hosting systems. Local low-privilege access can be more realistic in multi-tenant environments than on a single-purpose server, but the exact initial-access path depends on the individual environment and is not established by the CVE alone.
Which cPanel and WHM builds are affected?
Current reporting that reviewed Acronis advisory SEC-10986 identifies Linux Acronis Backup plugin builds earlier than 1.9.3.1021 as affected.
Acronis’s own release history confirms that 1.9.3 HF3 build 1021 contains security fixes. The release history also shows why administrators should verify the exact build rather than relying on the version number alone:
| cPanel & WHM release | Build | Remediation state |
|---|---|---|
| 1.9.3 | 978 | Below verified security-fix build |
| 1.9.3 HF1 | 982 | Below verified security-fix build |
| 1.9.3 HF2 | 998 | Below verified security-fix build |
| 1.9.3 HF3 | 1021 | Verified security-fix build |
| 1.9.4 | 1022 | Later than verified fixed build |
If your console only shows “1.9.3,” verify the hotfix/build before marking the vulnerability remediated.
Which Plesk builds are affected?
Current SEC-10986 reporting identifies Linux Acronis Backup extension builds earlier than 1.8.11.638 as affected.
Acronis’s release notes confirm version 1.8.11 build 638 as a release containing security fixes. Administrators should therefore move vulnerable Plesk integrations to build 638 or a later supported release.
Has exploitation been observed against both cPanel and Plesk?
No evidence reviewed by TPS establishes observed exploitation against both products.
Acronis-attributed reporting says the company saw limited, targeted exploitation involving cPanel & WHM deployments. Both integrations are affected by the vulnerability, but current evidence does not establish that Plesk exploitation has been observed in the wild.
That distinction should remain explicit: affected does not automatically mean observed exploited.
Does CVE-2026-87886 require local access?
Current evidence supports a local low-privilege prerequisite. The vulnerability then allows privilege escalation on the affected Linux host.
TPS did not establish an attack path where an unauthenticated external host can directly exploit the vulnerable Acronis integration over the network and immediately gain root access. Administrators should therefore avoid using remote-RCE wording unless Acronis or another controlling source changes the technical description.
Acronis CVE-2026-87886 administrator checklist
Inventory the integration
Identify every Linux server using the Acronis Backup plugin for cPanel & WHM or the Acronis Backup extension for Plesk.
Check the exact build
For cPanel & WHM, verify the hotfix/build and do not treat plain 1.9.3 as proof of remediation. For Plesk, verify the build number as well as the version.
Patch cPanel & WHM
Move affected systems to Acronis Backup 1.9.3 HF3 build 1021 or a later supported release.
Patch Plesk
Move affected systems to Acronis Backup 1.8.11 build 638 or a later supported release.
Review previous exposure
For systems that ran vulnerable builds, consider whether forensic or incident triage is required by your obligations, policy and risk profile, especially for cPanel & WHM where exploitation has been reported.
Verify the new state
Record the post-update version and build so the asset can be shown to be at or above the verified fixed release.
Is installing the update enough after known exploitation?
Installing a fixed build removes the known vulnerable software state, but it does not automatically prove that a previously vulnerable server was never compromised.
CISA’s KEV required-action framework for this entry refers to vendor mitigation and applicable forensic-triage requirements. Organizations covered by federal directives should follow the controlling CISA requirements. Other organizations should apply their own incident-response and risk policies rather than assuming that “patched” necessarily means “clean.”
No specific Acronis indicator-of-compromise set was established in the evidence reviewed by TPS, so this article does not invent file paths, commands, log patterns or malware indicators.
What does the September 19 CISA deadline apply to?
The September 19, 2026 date is the remediation deadline associated with the KEV entry for applicable federal systems under CISA’s governing directive framework.
Private companies, hosting providers and MSPs should not be told that the date is automatically a statutory deadline for them. The practical significance for non-federal organizations is that CISA has elevated the flaw as known exploited and expects rapid risk-based remediation.
Are ransomware attacks linked to this CVE?
CISA’s current KEV data does not establish known ransomware use for CVE-2026-87886. TPS also did not verify a named ransomware operation, threat actor or broader campaign tied to the vulnerability.
Do not infer ransomware involvement merely because a vulnerability appears in KEV.
How do you prove remediation?
For the software state, remediation is demonstrated by verifying that the affected integration is at or above the supported fixed build:
- cPanel & WHM: 1.9.3 HF3 build 1021 or later.
- Plesk: 1.8.11 build 638 or later.
Where compromise review is required, software version evidence is only one part of closure. The organization may also need to document forensic or incident-response findings according to its regulatory, contractual or internal requirements.
Verification note
ThePulseSignal reviewed the CISA KEV state, Acronis’s cPanel & WHM and Plesk release histories, and current reporting that directly cites or describes Acronis advisory SEC-10986. The fixed builds are supported by Acronis’s own release notes. Detailed SEC-10986 text was not directly retrievable in the research environment, so the affected-range and exploitation-scope details are presented within that evidence boundary.
Limitations and unresolved facts
The number of exploited hosts is unknown. TPS did not establish observed Plesk exploitation, a named attacker, ransomware use, a complete attack chain or a vendor IOC set. Acronis and CISA may revise the advisory, affected versions, forensic guidance or exploitation information after publication.
Bottom line
Acronis CVE-2026-87886 is now a CISA KEV-listed, known-exploited privilege-escalation vulnerability affecting Linux Acronis Backup integrations for cPanel & WHM and Plesk.
For cPanel & WHM, verify that the plugin is at 1.9.3 HF3 build 1021 or later. For Plesk, verify 1.8.11 build 638 or later. Current exploitation reporting specifically concerns cPanel & WHM, while Plesk is affected but not established as exploited. Previously vulnerable systems may also require forensic review rather than a patch-only closure decision.