DEV Community

Cover image for Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins

Summary

Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.

Take Action:

Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)