Acronis patches a privilege escalation in its cPanel, Plesk and DirectAdmin backup plugins
On September 16, 2026, CISA added a local privilege escalation (CVE-2026-87886) caused by overly permissive default permissions in the Acronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin to its KEV catalog. Update to the fixed builds — the September 19 federal deadline has already passed.