<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Acronis on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/acronis/</link>
    <description>Recent content in Acronis on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Wed, 16 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/acronis/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Acronis Backup Incorrect Default Permissions Vulnerability</title>
      <link>https://www.phllaps.net/posts/acronis-backup-incorrect-default-permissions-vulnerability/</link>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/acronis-backup-incorrect-default-permissions-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#6b7280;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: UNKNOWN&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Acronis Backup plugin for cPanel &amp;amp; WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-09-16) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-87886.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-87886 affects the Acronis Backup plugin for cPanel &amp;amp; WHM and the equivalent extension for Plesk. The flaw is an incorrect default permissions issue, which typically means files, directories, or configuration data tied to the plugin are left accessible in a way that allows a local user without the intended privilege level to read, modify, or otherwise interact with them.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
