Act
active
Acronis cPanel/WHM/Plesk backup plugin actively exploited via LPE flaw
- Engineer — Act: Acronis itself warns of in-the-wild exploitation of a Linux local privilege escalation in its backup plugin for cPanel, WHM, and Plesk — patch the Acronis backup plugin to the fixed version immediately on any hosting or panel infrastructure you operate.
- SOC/IR — Plan: Active exploitation is claimed but no IOCs or ATT&CK-mapped TTPs are published yet; build or tune detection for anomalous privilege escalation events on Linux hosts running cPanel/WHM/Plesk and revisit when indicators surface.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.