Published Tuesday, September 15, 2026 at 05:33 PM PT

BLUF: Acronis has warned of an actively exploited vulnerability affecting its cPanel backup plugin. Exploitation is confirmed in the wild, but technical scope, CVE assignment, affected versions, and patch availability are not yet confirmed in available reporting. Organizations running Acronis backup solutions integrated with cPanel should assume risk and monitor for official Acronis guidance.
DETAILS
- Source: Acronis public warning (reported by BleepingComputer); active exploitation confirmed as of report date
- Affected product: Acronis backup plugin for cPanel
- Attack status: Actively exploited in the wild β no proof-of-concept required for adversaries to target
- Known technical scope: NOT YET CONFIRMED β CVE number, vulnerability type (RCE, auth bypass, etc.), affected versions, and patch status are not specified in available reporting
- Targeting: Likely cPanel/WHM hosting environments and backup infrastructure; scope unclear
IMPACT
- Scope: Unknown β affects any organization deploying Acronis backup integration with cPanel
- Risk level: High (active exploitation + plugin runs on critical backup infrastructure)
- Business impact: Potential unauthorized access to backup systems, backup integrity compromise, lateral movement into cPanel environments
RECOMMENDED ACTIONS β IMMEDIATE
- Locate all cPanel + Acronis integrations β inventory servers running the Acronis cPanel backup plugin
- Monitor Acronis security advisories (status.acronis.com, security@acronis.com) for CVE announcement, affected version list, and patch release
- Do NOT wait for internal change control β patch immediately upon Acronis release
- Isolate if possible β if exploitation vectors are confirmed, consider temporarily disabling plugin until patched (if operationally feasible)
- Check backup logs β review Acronis and cPanel logs for suspicious activity post-dating this warning
- Prepare rollback β identify which systems depend on Acronis backups so patch/rollback can be rapid if needed
MONITORING REQUIRED
- Acronis official security page for CVE, patch release, and exploitation IOCs
- CISA alerts for any advisory issuance
- Acronis customer mailing list
STATUS: Information incomplete. Reissue with full technical details (CVE, versions, patch status) as soon as Acronis or CISA publishes.
Recent high-severity events at publish time:

