Acronis has patched a high-severity local privilege escalation flaw, tracked as CVE-2026-87886, in its backup add-ons for cPanel/WHM and Plesk. The company says it has seen limited, targeted exploitation attempts against affected deployments, based on a report from one potentially affected customer. Fixed versions are 1.9.3 HF3 for cPanel/WHM and 1.8.11 for Plesk.
bleepingcomputer.com
· 2026-09-15
Acronis has published a checklist defining six required capabilities for MSP ransomware protection services, spanning exposure reduction, early detection, round-the-clock incident response, isolated backup preservation, clean recovery, and consistent enforcement across all client tenants. The guidance draws on Acronis's Cyberthreats Report, which documented 143 ransomware victims among MSPs, IT service providers and telecoms in 2025, with phishing responsible for 52% of initial breaches and unpatched systems for 27%.
bleepingcomputer.com
· 2026-09-02