LATEST View all updates

Acronis CVE-2026-87886: KEV Patch Guide for cPanel and Plesk

CISA lists the Acronis flaw as exploited. Check exact cPanel and Plesk builds and patch vulnerable systems.

Hosting security administrator checking Acronis backup integration builds after CVE-2026-87886 entered CISA KEV

Signal Brief

  • CISA lists Acronis CVE-2026-87886 as known exploited, with a September 19 federal remediation deadline.
  • cPanel & WHM systems should run Acronis Backup 1.9.3 HF3 build 1021 or later; plain version 1.9.3 is not enough to prove remediation.
  • Plesk systems should run Acronis Backup 1.8.11 build 638 or later; observed exploitation of Plesk was not established in the reviewed evidence.
  • The flaw is a local privilege escalation, and previously vulnerable systems may need forensic triage in addition to software updating.

Acronis CVE-2026-87886 is now in the CISA Known Exploited Vulnerabilities catalog, raising the patch priority for hosting environments using affected Acronis Backup integrations with cPanel & WHM or Plesk. This is a local privilege-escalation flaw linked to insecure or incorrect file permissions, not an established unauthenticated remote-code-execution vulnerability.

Which Acronis Backup versions need to be patched?

For Linux systems, current evidence indicates that Acronis Backup for cPanel & WHM should be updated to 1.9.3 HF3 build 1021 or later. Acronis Backup for Plesk should be updated to 1.8.11 build 638 or later.

For cPanel & WHM, checking only the visible version label is not enough: several builds exist under the 1.9.3 family, and the security-fix release is specifically HF3 build 1021.

Infographic showing Acronis CVE-2026-87886 build checks for cPanel and Plesk plus forensic triage after patching
The remediation path requires exact build verification and may also require forensic triage for previously vulnerable systems.

Why did CISA add CVE-2026-87886 to KEV?

CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on September 16, 2026. KEV inclusion means exploitation is known to have occurred and gives the vulnerability a materially higher operational patch priority than an ordinary unexploited CVE.

The CISA entry lists a September 19 remediation due date for relevant federal assets. That deadline should not be described as a universal legal deadline for every private company. Private hosting providers and enterprises can still use KEV inclusion as a strong risk-based patching signal.

What kind of vulnerability is CVE-2026-87886?

The vulnerability is a local privilege-escalation issue associated with insecure or incorrect default file permissions in affected Acronis Backup control-panel integrations.

Current vendor-attributed reporting describes exploitation by a low-privileged attacker who already has access to the vulnerable Linux system and can then escalate privileges. TPS therefore does not describe CVE-2026-87886 as a direct unauthenticated remote attack from the internet.

That distinction matters on shared hosting systems. Local low-privilege access can be more realistic in multi-tenant environments than on a single-purpose server, but the exact initial-access path depends on the individual environment and is not established by the CVE alone.

Which cPanel and WHM builds are affected?

Current reporting that reviewed Acronis advisory SEC-10986 identifies Linux Acronis Backup plugin builds earlier than 1.9.3.1021 as affected.

Acronis’s own release history confirms that 1.9.3 HF3 build 1021 contains security fixes. The release history also shows why administrators should verify the exact build rather than relying on the version number alone:

cPanel & WHM release Build Remediation state
1.9.3 978 Below verified security-fix build
1.9.3 HF1 982 Below verified security-fix build
1.9.3 HF2 998 Below verified security-fix build
1.9.3 HF3 1021 Verified security-fix build
1.9.4 1022 Later than verified fixed build

If your console only shows “1.9.3,” verify the hotfix/build before marking the vulnerability remediated.

Which Plesk builds are affected?

Current SEC-10986 reporting identifies Linux Acronis Backup extension builds earlier than 1.8.11.638 as affected.

Acronis’s release notes confirm version 1.8.11 build 638 as a release containing security fixes. Administrators should therefore move vulnerable Plesk integrations to build 638 or a later supported release.

Has exploitation been observed against both cPanel and Plesk?

No evidence reviewed by TPS establishes observed exploitation against both products.

Acronis-attributed reporting says the company saw limited, targeted exploitation involving cPanel & WHM deployments. Both integrations are affected by the vulnerability, but current evidence does not establish that Plesk exploitation has been observed in the wild.

That distinction should remain explicit: affected does not automatically mean observed exploited.

Does CVE-2026-87886 require local access?

Current evidence supports a local low-privilege prerequisite. The vulnerability then allows privilege escalation on the affected Linux host.

TPS did not establish an attack path where an unauthenticated external host can directly exploit the vulnerable Acronis integration over the network and immediately gain root access. Administrators should therefore avoid using remote-RCE wording unless Acronis or another controlling source changes the technical description.

Acronis CVE-2026-87886 administrator checklist

Inventory the integration

Identify every Linux server using the Acronis Backup plugin for cPanel & WHM or the Acronis Backup extension for Plesk.

Check the exact build

For cPanel & WHM, verify the hotfix/build and do not treat plain 1.9.3 as proof of remediation. For Plesk, verify the build number as well as the version.

Patch cPanel & WHM

Move affected systems to Acronis Backup 1.9.3 HF3 build 1021 or a later supported release.

Patch Plesk

Move affected systems to Acronis Backup 1.8.11 build 638 or a later supported release.

Review previous exposure

For systems that ran vulnerable builds, consider whether forensic or incident triage is required by your obligations, policy and risk profile, especially for cPanel & WHM where exploitation has been reported.

Verify the new state

Record the post-update version and build so the asset can be shown to be at or above the verified fixed release.

Is installing the update enough after known exploitation?

Installing a fixed build removes the known vulnerable software state, but it does not automatically prove that a previously vulnerable server was never compromised.

CISA’s KEV required-action framework for this entry refers to vendor mitigation and applicable forensic-triage requirements. Organizations covered by federal directives should follow the controlling CISA requirements. Other organizations should apply their own incident-response and risk policies rather than assuming that “patched” necessarily means “clean.”

No specific Acronis indicator-of-compromise set was established in the evidence reviewed by TPS, so this article does not invent file paths, commands, log patterns or malware indicators.

What does the September 19 CISA deadline apply to?

The September 19, 2026 date is the remediation deadline associated with the KEV entry for applicable federal systems under CISA’s governing directive framework.

Private companies, hosting providers and MSPs should not be told that the date is automatically a statutory deadline for them. The practical significance for non-federal organizations is that CISA has elevated the flaw as known exploited and expects rapid risk-based remediation.

Are ransomware attacks linked to this CVE?

CISA’s current KEV data does not establish known ransomware use for CVE-2026-87886. TPS also did not verify a named ransomware operation, threat actor or broader campaign tied to the vulnerability.

Do not infer ransomware involvement merely because a vulnerability appears in KEV.

How do you prove remediation?

For the software state, remediation is demonstrated by verifying that the affected integration is at or above the supported fixed build:

  • cPanel & WHM: 1.9.3 HF3 build 1021 or later.
  • Plesk: 1.8.11 build 638 or later.

Where compromise review is required, software version evidence is only one part of closure. The organization may also need to document forensic or incident-response findings according to its regulatory, contractual or internal requirements.

Verification note

ThePulseSignal reviewed the CISA KEV state, Acronis’s cPanel & WHM and Plesk release histories, and current reporting that directly cites or describes Acronis advisory SEC-10986. The fixed builds are supported by Acronis’s own release notes. Detailed SEC-10986 text was not directly retrievable in the research environment, so the affected-range and exploitation-scope details are presented within that evidence boundary.

Limitations and unresolved facts

The number of exploited hosts is unknown. TPS did not establish observed Plesk exploitation, a named attacker, ransomware use, a complete attack chain or a vendor IOC set. Acronis and CISA may revise the advisory, affected versions, forensic guidance or exploitation information after publication.

Bottom line

Acronis CVE-2026-87886 is now a CISA KEV-listed, known-exploited privilege-escalation vulnerability affecting Linux Acronis Backup integrations for cPanel & WHM and Plesk.

For cPanel & WHM, verify that the plugin is at 1.9.3 HF3 build 1021 or later. For Plesk, verify 1.8.11 build 638 or later. Current exploitation reporting specifically concerns cPanel & WHM, while Plesk is affected but not established as exploited. Previously vulnerable systems may also require forensic review rather than a patch-only closure decision.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial cybersecurity guidance on Acronis CVE-2026-87886. Known exploitation and fixed builds are supported by CISA, Acronis release notes and current vendor-attributed reporting, but victim count, Plesk exploitation, indicators of compromise and the full attack chain remain unresolved. Verify current Acronis and CISA guidance before consequential patching, forensic or incident-response action.