Defensive self-check · CISA KEV 2026-09-16
Acronis Backup cPanel plugin CVE-2026-87886 self-check
CISA added CVE-2026-87886 on 2026-09-16. It concerns weak default permissions in the Acronis Backup cPanel/WHM plugin and the Plesk extension. Check a server you administer. No exploit steps are included.
Check these three things
- Plugin version. In WHM open Plugins → Acronis Backup, or the matching Plesk extension page, and compare the version with the Acronis fixed release.
- File permissions. Review the plugin directory permissions against the vendor's hardened defaults after the update.
- Accounts and jobs. Review WHM accounts and the backup job history for jobs or users created outside your change record.
What to do
Update the plugin or extension from the vendor package, then recheck permissions. The cPanel check only sees the public fingerprint, so confirm the plugin version inside WHM.
Vendor record: CISA KEV catalog, entry CVE-2026-87886.