CVE-2026-87886
Vendor advisory + active exploitation claimed; no KEV list or public PoC yet limits to likely-hack range.
What: Linux local privilege escalation (CVSS 7.8) in Acronis backup plugins for cPanel, WHM, and Plesk affecting server hosting control panel integrations.
Why it matters: Acronis disclosed active limited exploitation in the wild; vendor has issued patches (1.9.3 HF3, 1.8.11+). Social chatter reflects legitimate advisory coverage and defender urgency to patch affected backup integrations.
Where it's seen: Bleeping Computer coverage of Acronis advisory; multiple posts flagging patch versions and active exploitation; no public PoC confirmed yet but vendor disclosure confirms real-world attacks.
RISK: HIGH — Active exploitation by limited threat actors; affects widely-deployed backup infrastructure.
No NVD details ingested for this CVE yet.