Skip to content

CVE-2026-87886 explained: the Acronis Backup flaw and how to fix it

By Donovan Brown
September 20, 2026
8 sections
CVE-2026-87886 explained: the Acronis Backup flaw and how to fix it — Cyber Security article cover card from LayerLogix, with a warning alert icon
01

Introduction

CVE-2026-87886 is a security flaw in certain Acronis Backup plugins that run on Linux-based web hosting control panels. It lets someone who already has limited access on the server grant themselves full administrator rights. If you don't run Acronis Backup on a Linux server, you can stop reading now.

02

Does this affect you?

The two-minute check

  1. Log in to the control panel on the server where you installed Acronis Backup.
  2. Open the Acronis Backup plugin or extension settings screen.
  3. Find the version or build number, usually shown near the plugin name.
  4. Compare that number to the fixed builds listed in the vendor advisory linked below.

When you can stop reading

The record only names Acronis Backup plugins for Linux-based control panels, plus the Linux kernel component. If you don't install Acronis Backup as a plugin on a Linux server, this flaw does not apply to you. If your backups run through a different product or setup entirely, you can close this tab.

03

How bad is it, honestly?

What the official record says

The National Vulnerability Database (NVD) record does not list a Common Vulnerability Scoring System (CVSS) score for this flaw. We won't guess one on your behalf.

The Exploit Prediction Scoring System (EPSS) score is 0.25%, placing it at the 17.33rd percentile among scored vulnerabilities (FIRST.org). EPSS forecasts exploitation activity in the next 30 days. It does not measure how severe the flaw itself is.

This flaw sits on the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 16, 2026. That listing means criminals are already using this flaw, not just theorizing about it.

The vendor has published fixed build numbers in its security advisory.

What that means for a business like yours

This is a local privilege escalation bug. Someone needs some existing access to your server before they can use it. Insecure file permissions let that person grant themselves full administrator rights they should not have. Once they have that level of access, they can read, change or delete anything on that server, including your backups.

04

What to do about it, step by step

If someone else manages your IT

Send this to your provider. Keep it short.

  • "Please check if we run Acronis Backup plugins on any Linux control panel servers."
  • "If we do, please confirm the build number is current per CVE-2026-87886."
  • "Please tell me when this is done."

If you don't have an IT provider yet, our managed IT services team can take this on for you.

If you manage it yourself

  1. Log in to each Linux server where you installed Acronis Backup.
  2. Open the control panel and find the Acronis Backup plugin page.
  3. Check the build number shown against the vendor advisory.
  4. If it's older than the fixed build, run the plugin's update option.
  5. Restart the control panel service if the advisory tells you to.
  6. Confirm the new build number appears on the plugin page.
05

How long you have

This flaw is already being used by attackers, so the honest answer is now, not later. Federal agencies were given until September 19, 2026 to fix this on their own systems (CISA KEV catalog). Your business isn't bound by that federal deadline. The same urgency still applies to you. Treat this as something to fix this week, not this quarter.

06

How to check it actually worked

Don't just trust an update progress bar. Log back in to the Acronis Backup plugin page after the update finishes. Confirm the build number matches or exceeds the fixed version listed in the vendor advisory. If the number hasn't changed, the update did not apply, and you need to run it again.

07

What to do if you can't patch right now

If you can't patch immediately, limit who can log in to the affected server. Remove any user accounts you don't recognize or no longer need. Restrict administrator-level access to only the people who truly need it, which is a good use of privileged access management. Watch server logs more closely than usual while the plugin stays unpatched. None of these steps fix the flaw itself. They only reduce the chance someone with low-level access can exploit it before you patch.

08

Frequently Asked Questions

Do I have to do anything if I don't use Acronis Backup on a Linux server?

No. This flaw only affects Acronis Backup plugins on Linux-based control panels, plus the Linux kernel component named in the record. If that's not your setup, this doesn't apply to you.

Will patching break anything?

The record doesn't say. Vendor patches for plugins like this are usually routine. Even so, back up your current configuration before updating any production server.

Does a low EPSS score mean I can ignore this?

No. The score reflects a low chance of exploitation in the next 30 days across all tracked vulnerabilities, not that this specific flaw is safe. It's already on the KEV catalog, which means it's already being used somewhere. Patch it regardless of the score.

We're a small office. Does this really apply to us?

If you run Acronis Backup plugins on a Linux control panel server, size doesn't matter. Attackers automate scans for known flaws like this one. Small businesses get checked just as often as large ones.

What if we handle sensitive client data?

If you handle health records or financial data, backup security matters even more. Review your obligations under HIPAA or the FTC Safeguards Rule alongside this patch.

LayerLogix brings 20+ years of experience and 100% Texas-based support to businesses across the Woodlands, Round Rock, Houston, Dallas-Fort Worth and Austin. Our team offers business-hours support with after-hours emergency response, plus cybersecurity services built for exactly this kind of patching work. If you want a second set of eyes on your servers, request a free IT assessment or contact us today.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call