Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: backup-plugin (2 articles)Clear

Acronis cPanel backup plugin flaw exploited to escalate privileges on hosting servers

Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.

Check
Update the Acronis Backup plugin for cPanel and WHM to the fixed version immediately, and update the Plesk extension too, then review shared servers for signs of privilege escalation and unauthorized access.
Affected
Web hosts and managed service providers running the Acronis Backup plugin for cPanel and WHM (CVE-2026-87886); an attacker with a foothold can escalate privileges to reach backups, system files, and tenants' data.
Fix
Patch the backup plugin and extension, tighten file permissions and account isolation on shared hosting, monitor for privilege escalation and backup access, and treat a compromised hosting account as a server-wide risk.

WordPress backup plugin flaw lets attackers hijack sites through a poisoned import

A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.

Check
Update All-in-One WP Migration and Backup to 7.110 or later across all WordPress sites, and review sites for suspicious trackback comments, unexpected admin accounts, and unfamiliar files.
Affected
WordPress sites running All-in-One WP Migration and Backup through 7.109 (CVE-2026-19949); an unauthenticated attacker can plant SQL injection that leaks the plugin's secret key, enabling a malicious archive import and site takeover.
Fix
Patch the plugin, scan for web shells and unexpected files, audit administrator accounts, rotate WordPress secrets, disable trackbacks if not needed, and put a web application firewall in front of the site.