CVE-2026-87886: Acronis Backup Incorrect Default Permissions — CISA KEV Entry and 3-Day Remediation Window
CISA added CVE-2026-87886, an incorrect default permissions flaw in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to the KEV catalog on 2026-09-16 with a 2026-09-19 due date. Patch or mitigate now.

CVE-2026-87886: Acronis Backup Incorrect Default Permissions — CISA KEV Entry and 3-Day Remediation Window
TL;DR
CISA added CVE-2026-87886, an incorrect default permissions vulnerability in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to the Known Exploited Vulnerabilities (KEV) catalog on 2026-09-16, with a federal remediation due date of 2026-09-19. If you run Acronis Backup on cPanel & WHM or Plesk, treat this as a priority patch: inventory affected hosts today, apply the vendor mitigation from Acronis advisory SEC-10986, and verify that permissions are corrected before closing the ticket.
What is this vulnerability?
- CVE ID: CVE-2026-87886
- Vendor / product: Acronis / Backup (plugin for cPanel & WHM; extension for Plesk)
- Vulnerability name: Acronis Backup Incorrect Default Permissions Vulnerability
- Weakness: CWE-276 (Incorrect Default Permissions)
- Impact: Could allow for privilege escalation
- CISA KEV status: Yes — added 2026-09-16
- CISA due date: 2026-09-19
- Known ransomware use: Unknown
CISA's required action is to apply mitigations in accordance with vendor instructions, consistent with BOD 26-04 Prioritizing Security Updates Based on Risk and CISA's Forensics Triage Requirements implementation guidance. Where mitigations are unavailable, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV vs CVSS vs EPSS
| Signal | What it measures | How to use it for this CVE |
|---|---|---|
| CISA KEV | Confirmed in-the-wild exploitation, with a binding federal remediation due date | Authoritative trigger here: CVE-2026-87886 was added 2026-09-16 with a 2026-09-19 due date. Escalate to a priority patch ticket immediately. |
| CVSS | Technical severity of the vulnerability in isolation | Not provided in the source intel for this CVE. Do not infer a score — rely on KEV status and vendor guidance for prioritization. |
| EPSS | Modeled probability of exploitation activity in the near term | Not provided in the source intel for this CVE. KEV listing already confirms exploitation, so EPSS is not needed to justify urgency. |
Step-by-step remediation
- Inventory. Identify every host running the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Include managed hosting fleets, reseller environments, and any shadow installs.
- Assess exposure. Determine which of those assets are internet-facing or otherwise reachable by untrusted users, per BOD 26-04 guidance on evaluating each asset's internet exposure.
- Patch or mitigate. Apply mitigations in accordance with the vendor's instructions in Acronis advisory SEC-10986. If mitigations are unavailable for a given deployment, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product.
- Verify. Confirm the fix is applied and that default permissions on the affected components have been corrected. Re-check that no residual world-readable/writable or overly permissive settings remain.
- Close the ticket. Document the CVE, the KEV due date (2026-09-19), the action taken, and the verification evidence. Align ticket closure with BOD 26-04 and the Forensics Triage Requirements guidance.
FAQ
Is CVE-2026-87886 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-16.
What is the CISA due date for CVE-2026-87886? The federal remediation due date is 2026-09-19 — a three-day window from the KEV addition date.
Is this vulnerability internet-facing? The source intel does not state internet exposure directly. CISA's required action explicitly places responsibility on stakeholders to evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. Treat cPanel & WHM and Plesk hosts that are reachable from untrusted networks as the highest priority.
Is there a ransomware tie to CVE-2026-87886? Known ransomware use is listed as Unknown in the source intel. Absence of a confirmed ransomware link does not lower the priority — KEV listing alone confirms exploitation.
What is the weakness type? CWE-276, Incorrect Default Permissions, which could allow for privilege escalation.
What should we do if we cannot patch in time? Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and consult Acronis advisory SEC-10986 for vendor-specific options.