← Back to blog
Blog Detail

CVE-2026-87886: Acronis Backup Incorrect Default Permissions — CISA KEV Entry and 3-Day Remediation Window

CISA added CVE-2026-87886, an incorrect default permissions flaw in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to the KEV catalog on 2026-09-16 with a 2026-09-19 due date. Patch or mitigate now.

Trusteed Team
Trusteed Editorial
Written On
Sep 22, 2026
Category
KEV
Read Time
4 min read
  • CVE-2026-87886
  • KEV
  • CISA
  • Acronis
  • Backup
  • cPanel
  • WHM
  • Plesk
  • CWE-276
  • privilege escalation
  • BOD 26-04
CVE-2026-87886: Acronis Backup Incorrect Default Permissions — CISA KEV Entry and 3-Day Remediation Window

CVE-2026-87886: Acronis Backup Incorrect Default Permissions — CISA KEV Entry and 3-Day Remediation Window

TL;DR

CISA added CVE-2026-87886, an incorrect default permissions vulnerability in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, to the Known Exploited Vulnerabilities (KEV) catalog on 2026-09-16, with a federal remediation due date of 2026-09-19. If you run Acronis Backup on cPanel & WHM or Plesk, treat this as a priority patch: inventory affected hosts today, apply the vendor mitigation from Acronis advisory SEC-10986, and verify that permissions are corrected before closing the ticket.

What is this vulnerability?

  • CVE ID: CVE-2026-87886
  • Vendor / product: Acronis / Backup (plugin for cPanel & WHM; extension for Plesk)
  • Vulnerability name: Acronis Backup Incorrect Default Permissions Vulnerability
  • Weakness: CWE-276 (Incorrect Default Permissions)
  • Impact: Could allow for privilege escalation
  • CISA KEV status: Yes — added 2026-09-16
  • CISA due date: 2026-09-19
  • Known ransomware use: Unknown

CISA's required action is to apply mitigations in accordance with vendor instructions, consistent with BOD 26-04 Prioritizing Security Updates Based on Risk and CISA's Forensics Triage Requirements implementation guidance. Where mitigations are unavailable, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEV vs CVSS vs EPSS

Signal What it measures How to use it for this CVE
CISA KEV Confirmed in-the-wild exploitation, with a binding federal remediation due date Authoritative trigger here: CVE-2026-87886 was added 2026-09-16 with a 2026-09-19 due date. Escalate to a priority patch ticket immediately.
CVSS Technical severity of the vulnerability in isolation Not provided in the source intel for this CVE. Do not infer a score — rely on KEV status and vendor guidance for prioritization.
EPSS Modeled probability of exploitation activity in the near term Not provided in the source intel for this CVE. KEV listing already confirms exploitation, so EPSS is not needed to justify urgency.

Step-by-step remediation

  1. Inventory. Identify every host running the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Include managed hosting fleets, reseller environments, and any shadow installs.
  2. Assess exposure. Determine which of those assets are internet-facing or otherwise reachable by untrusted users, per BOD 26-04 guidance on evaluating each asset's internet exposure.
  3. Patch or mitigate. Apply mitigations in accordance with the vendor's instructions in Acronis advisory SEC-10986. If mitigations are unavailable for a given deployment, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product.
  4. Verify. Confirm the fix is applied and that default permissions on the affected components have been corrected. Re-check that no residual world-readable/writable or overly permissive settings remain.
  5. Close the ticket. Document the CVE, the KEV due date (2026-09-19), the action taken, and the verification evidence. Align ticket closure with BOD 26-04 and the Forensics Triage Requirements guidance.

FAQ

Is CVE-2026-87886 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-16.

What is the CISA due date for CVE-2026-87886? The federal remediation due date is 2026-09-19 — a three-day window from the KEV addition date.

Is this vulnerability internet-facing? The source intel does not state internet exposure directly. CISA's required action explicitly places responsibility on stakeholders to evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. Treat cPanel & WHM and Plesk hosts that are reachable from untrusted networks as the highest priority.

Is there a ransomware tie to CVE-2026-87886? Known ransomware use is listed as Unknown in the source intel. Absence of a confirmed ransomware link does not lower the priority — KEV listing alone confirms exploitation.

What is the weakness type? CWE-276, Incorrect Default Permissions, which could allow for privilege escalation.

What should we do if we cannot patch in time? Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and consult Acronis advisory SEC-10986 for vendor-specific options.

Related resources

Join Our Newsletter

Trusteed keeps you informed: emerging risks, platform updates, and practical guides for faster defense.