
Businesses depend on backups as a safety net. If a website is damaged, compromised, or accidentally changed, a usable backup may be the fastest way to restore normal operations.
However, backup software is still software. It requires updates, monitoring, and security maintenance just like a business computer, firewall, or website plugin.
Acronis recently disclosed a high-severity vulnerability affecting certain Linux versions of its Backup plugin for cPanel and WHM and its Backup extension for Plesk. Acronis said exploitation had been detected in limited, targeted attacks against the cPanel and WHM plugin.
The vulnerability is identified as CVE-2026-87886. The Cybersecurity and Infrastructure Security Agency, or CISA, added it to its Known Exploited Vulnerabilities Catalog on September 16, 2026.
The affected products are specialized backup integrations used with common website-hosting control panels.
According to the Acronis security advisory, affected versions include:
Acronis describes the problem as insecure file permissions. In plain language, someone who already has limited access to an affected server may be able to obtain much greater control than that account should have.
This is not being described as a problem with every Acronis backup product. It applies to specific integrations used on Linux hosting servers. A business that only uses Acronis on Windows computers, for example, should not assume that those computers are affected by this particular vulnerability.
Many small businesses do not manage their website server directly. A web developer, hosting company, marketing agency, or managed service provider may handle the hosting account and its backups.
That arrangement is normal, but it can leave the business owner unsure about which products are running behind the scenes.
If an affected server were compromised, the potential business consequences could include:
A backup system should support recovery. It should not become an overlooked route to greater control of the server.
You do not need to become a server expert. Send your provider a short, direct request:
Ask for confirmation rather than accepting a general response such as “updates are automatic.” Automatic updating is useful, but version verification provides clearer evidence that this specific issue has been addressed.
Because exploitation has already been reported, installing the corrected version should be treated as the first step rather than the only step.
The hosting provider should also consider reviewing:
This review should be handled by the responsible hosting or IT professional. Business owners should not start deleting server files or changing unfamiliar settings without understanding the effect on the website and its backups.
A completed backup notification does not prove that a business can recover successfully.
A sound website recovery plan should answer:
These questions matter whether or not a business uses the affected Acronis products.
This incident does not mean businesses should stop using backup software. It demonstrates why backup systems must be included in normal security management.
Identify who manages the website, determine whether the affected integration is present, verify the corrected version, and confirm that a usable recovery plan exists. If the provider cannot answer those questions clearly, the business has discovered an important gap that deserves attention.

Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day

Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety

I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!

I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.

Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.

It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.

Himala and his team from Cybernetic Networks, Inc. has been an integral part of our successful retail business for the past 20 years. He is extraordinarily knowledgable and always available for our IT needs. Thanks to Himala and his team we are always up and running.