CISA added CVE-2026-87886, an incorrect default permissions vulnerability in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline.
What Is It
CVE-2026-87886 is an incorrect default permissions vulnerability (CWE-276) in Acronis Backup. According to CISA's KEV entry, the Acronis Backup plugin for cPanel & WHM and the extension for Plesk ship with default permissions that could allow for privilege escalation.
No NVD record data, CVSS score, severity rating, or vector string is available for this CVE at the time of writing; the NVD entry returned empty. Vendor details are published in Acronis security advisory SEC-10986.
Why It Matters
Inclusion in the KEV catalog means CISA has evidence of active exploitation in the wild. The remediation window CISA assigned is unusually tight: per the KEV catalog entry, the CVE was added 2026-09-16 with a due date of 2026-09-19, three days later.
The same KEV entry flags this CVE as requiring forensic triage, indicating agencies are expected to investigate for signs of compromise rather than simply patch and move on. The catalog lists known ransomware campaign use as "Unknown."
The affected software runs on hosting control panels, which are typically multi-tenant and privileged by design. In that context, a privilege escalation path in a backup agent could plausibly open a route to broader control of the host and the tenants it serves, though neither CISA nor Acronis has published details of observed exploitation or its impact.
What's Vulnerable
- Acronis Backup plugin for cPanel & WHM
- Acronis Backup extension for Plesk
No specific version ranges or CPE identifiers are listed in the supplied KEV or NVD data. Consult the Acronis advisory for affected builds.
Patch Status
CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." For cloud services, follow the applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable.
Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline: 2026-09-19.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Acronis Security Advisory SEC-10986; https://security-advisory.acronis.com/advisories/SEC-10986
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- NVD, CVE-2026-87886, https://nvd.nist.gov/vuln/detail/CVE-2026-87886