Severity: HighAction: PatchExploitation: ExploitedCISA KEV
Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) is being actively exploited, CISA warns
CISA added CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Why it matters
CISA lists this as exploited in the wild. Unpatched Backup systems are exposed to active attacks now.
Patch
Apply the vendor's security update for Backup.
