Threat Brief — 2026-09-15 — Acronis cPanel Plugin Exploited in the Wild
Executive Summary
Today's feed contains one genuinely new threat-intelligence item: Acronis has disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk, with indications of active exploitation in the wild. Environments running these hosting-panel backup plugins should treat this as an immediate priority. The remaining findings either continue stories already covered in recent briefs without new developments, or cover non-security science and policy topics.
Top items
- Acronis cPanel/WHM/Plesk backup plugin — high-severity Linux LPE, actively exploited. Acronis disclosed a local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager, and Plesk on Linux. The flaw is described as potentially exploited in the wild, though specific victim details or a CVE identifier were not provided in the source reporting. Any hosting environment using the Acronis backup plugin through these control panels should verify patch availability immediately. (src: BleepingComputer)
Themes
Plugin and supply-chain risk persists across hosting platforms. This Acronis disclosure adds to an already heavy week for hosting-adjacent third-party software, including the Admin Menu Editor Pro supply-chain backdoor (first reported 2026-09-15) and the WooCommerce Wholesale Lead Capture plugin exploitation (first reported 2026-09-15). Hosting providers and their customers remain a recurring target surface, whether through compromised plugin distribution channels or unpatched plugin vulnerabilities. None of these ongoing stories had new developments in today's feed.
