CISA KEV Alert 17 Sept 2026, 00:00 UTC

CISA Flags Exploited Acronis Backup Flaw Allowing Privilege Escalation

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-87886 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Acronis Backup, specifically the plugin for cPanel & WHM and the extension for Plesk. Named the Acronis Backup Incorrect Default Permissions Vulnerability, it could allow an attacker to escalate privileges.

The flaw involves incorrect default permissions in Acronis Backup components. The available description indicates a privilege-escalation impact, but does not provide further technical details about the attack vector or exploitation requirements. No CVSS score or severity rating is currently available. Patch status is also unknown, and no patch advisory was provided in the supplied data. Organisations should consult Acronis advisory SEC-10986 for vendor guidance.

CISA’s KEV listing confirms that the vulnerability has been exploited in the wild. The available data does not confirm whether CVE-2026-87886 has been used in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 19 September 2026.

CISA requires agencies to apply mitigations in accordance with vendor instructions, while following the requirements of BOD 26-04, Prioritising Security Updates Based on Risk, and CISA’s Forensics Triage Requirements. Agencies must apply the relevant BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and comply with BOD 26-04 patching guidance.

Although the deadline applies directly to FCEB agencies, all organisations should review their exposure to Acronis Backup deployments using cPanel & WHM or Plesk.

See the NVD entry for CVE-2026-87886 and CISA’s KEV catalogue for full details: https://nvd.nist.gov/vuln/detail/CVE-2026-87886 and https://www.cisa.gov/known-exploited-vulnerabilities-catalog.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline