Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.
A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.