CVE-2026-87886 in Acronis Backup is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-09-16). Required action, remediation due date, ransomware association, EPSS score and vendor advisories.
CVE-2026-87886 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 2026-09-16. Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Wording published by CISA for this catalog entry. It is the baseline action, not a decision about your environment: whether this exposure matters for you depends on where the affected component runs, what it is exposed to and who owns it.
A catalog entry tells you a vulnerability is being exploited somewhere. It does not tell you whether it matters in your estate, who owns the fix, or what evidence an auditor will ask for later. That is the work VulnTrek does: it takes findings from the tools you already run, decides which exposure actually matters, routes it to an owner, keeps remediation human-approved and retains the lineage as evidence.
Sourced from public upstream advisories (CISA KEV, ENISA EUVD, vendor PSIRTs) mirrored daily. Informational only — not a remediation decision, not legal advice, and the absence of a record is not evidence of safety.