CuraSec

Act active

Acronis cPanel/WHM/Plesk backup plugin actively exploited via LPE flaw

2026-09-16 15:25 UTC · BleepingComputer · read the source ↗ #privilege-escalation#cpanel#acronis
  • Engineer — Act: Acronis itself warns of in-the-wild exploitation of a Linux local privilege escalation in its backup plugin for cPanel, WHM, and Plesk — patch the Acronis backup plugin to the fixed version immediately on any hosting or panel infrastructure you operate.
  • SOC/IR — Plan: Active exploitation is claimed but no IOCs or ATT&CK-mapped TTPs are published yet; build or tune detection for anomalous privilege escalation events on Linux hosts running cPanel/WHM/Plesk and revisit when indicators surface.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.