Cyber & AI intelligence
Wasteland.
Briefs indexed2686
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-87886 2026-09-16

CVE-2026-87886: Acronis Backup Permissions Flaw Added to CISA KEV

"CISA added CVE-2026-87886, an incorrect default permissions vulnerability in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a…"

CISA added CVE-2026-87886, an incorrect default permissions vulnerability in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline.

What Is It

CVE-2026-87886 is an incorrect default permissions vulnerability (CWE-276) in Acronis Backup. According to CISA's KEV entry, the Acronis Backup plugin for cPanel & WHM and the extension for Plesk ship with default permissions that could allow for privilege escalation.

No NVD record data, CVSS score, severity rating, or vector string is available for this CVE at the time of writing; the NVD entry returned empty. Vendor details are published in Acronis security advisory SEC-10986.

Why It Matters

Inclusion in the KEV catalog means CISA has evidence of active exploitation in the wild. The remediation window CISA assigned is unusually tight: per the KEV catalog entry, the CVE was added 2026-09-16 with a due date of 2026-09-19, three days later.

The same KEV entry flags this CVE as requiring forensic triage, indicating agencies are expected to investigate for signs of compromise rather than simply patch and move on. The catalog lists known ransomware campaign use as "Unknown."

The affected software runs on hosting control panels, which are typically multi-tenant and privileged by design. In that context, a privilege escalation path in a backup agent could plausibly open a route to broader control of the host and the tenants it serves, though neither CISA nor Acronis has published details of observed exploitation or its impact.

What's Vulnerable

No specific version ranges or CPE identifiers are listed in the supplied KEV or NVD data. Consult the Acronis advisory for affected builds.

Patch Status

CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." For cloud services, follow the applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable.

Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline: 2026-09-19.

Sources