Acronis Backup Flaw CVE-2026-87886 and Your Dental Practice
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
18778
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-18778,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

The Tool That Protects Your Data Is Now a Target: The Actively-Exploited Acronis Backup Flaw (CVE-2026-87886) and Why Backup Software Needs Guarding Too

A blue circuitry backup vault holding data-drive and record icons, with a hairline crack through which a red-orange intrusion thread slips inside, illustrating that the tool meant to protect the data has itself become an entry point

The Tool That Protects Your Data Is Now a Target: The Actively-Exploited Acronis Backup Flaw (CVE-2026-87886) and Why Backup Software Needs Guarding Too

There is a particular kind of unease that comes with this week’s advisory. Backup software is the thing a practice leans on when everything else has gone wrong – the safety net under the ransomware, the fire, the failed drive. So it lands differently when the backup tool itself turns out to be the way in. On September 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87886, a flaw in the Acronis Backup plugin for cPanel and WHM, to its Known Exploited Vulnerabilities catalog after confirming it is being used in real attacks. Before anyone panics: this specific flaw probably does not touch the workstation at your front desk. But the reason it matters to every dental practice is the lesson underneath it – the software that guards your data is a high-value target, and it needs guarding of its own.

What happened

CVE-2026-87886 is a local privilege-escalation vulnerability caused by incorrect default file permissions in Acronis’s backup add-on for the cPanel and WHM web-hosting control panels. Acronis rated it 7.8 on the CVSS scale – high severity. What pushed it onto CISA’s radar was not the score but the activity: security researchers observed limited, targeted exploitation in cPanel and WHM environments, and CISA’s listing set a federal remediation deadline of September 19, 2026. When a flaw moves from “theoretically bad” to “actively being used,” the calculus changes from patch-when-convenient to patch-now.

“Do we even run this?”

For most dental practices, honestly, the answer to this exact CVE is no – and we would rather tell you that than manufacture alarm. cPanel and WHM are web-hosting control panels: the software that runs on the server hosting a website, not the practice-management PC or the imaging workstation in the operatory. Where it can reach a dental practice is at the edges you may not think of as “yours”: the server that hosts your public practice website, and the hosting or IT provider environments that run cPanel to manage many customers at once. If your website lives on shared or managed hosting – and most do – it is worth a one-line email to whoever runs it asking whether they use the Acronis cPanel plugin and whether it has been patched. This is the same fourth-party-tool exposure we saw when a dental billing vendor’s breach dragged its client practices onto a ransomware leak site: the flaw was in someone else’s software, but the consequences flowed downhill.

Why backup software is a target in the first place

Here is the part that matters no matter which backup product you run. Backup software is, by design, one of the most privileged pieces of software in any environment. To do its job it needs deep, sweeping access – to read every file it protects and to write those files back during a restore. That is exactly the kind of access an attacker covets. And there is a second, colder reason it draws fire: modern ransomware crews hunt for backups and destroy them first. They know a practice with clean, current backups can restore and walk away without paying, so before they detonate they go looking for backup servers, repositories, and cloud credentials to delete or encrypt them. We saw this pattern spelled out in the Medusa ransomware advisory for healthcare: knock out the recovery option, and the victim’s leverage disappears. A vulnerability in the backup tool itself is a shortcut to both goals at once – privileged access and control over the one thing standing between the practice and a ransom demand.

Why “only local” is not the reassurance it sounds like

You may notice CVE-2026-87886 is a local privilege-escalation flaw, meaning an attacker needs to already be on the server to use it. That sounds comforting – and it is a genuine mitigating factor – but it is not a reason to relax. Real intrusions are built in stages. An attacker rarely walks straight into full control; they get a modest foothold first – a phished credential, a hijacked session, a separate flaw in some other service – and then chain that foothold into a privilege-escalation bug like this one to climb from “limited user” to “owns the whole machine.” A local flaw in privileged backup software is a perfect final rung on that ladder. Treating “local only” as “safe” is how a manageable foothold becomes a full compromise.

What to do this week

Whether or not the Acronis cPanel plugin is anywhere in your world, this advisory is a useful prompt to shore up backup security generally:

  • Find out where backup software actually runs. Inventory it honestly – the practice server, any cloud backup agent, and the hosting environment behind your website. If you use the Acronis cPanel/WHM plugin directly, apply the vendor’s patched release now; given the active exploitation and CISA deadline, this is not one to defer.
  • Ask your website host and IT provider the direct question. Do you run the affected Acronis plugin, and is it patched? A provider who can answer crisply has already done the work; one who cannot has told you something too.
  • Keep at least one copy offline or immutable. Follow the 3-2-1 rule – three copies, on two kinds of media, with one kept offline or air-gapped. A backup an attacker can reach and delete over the network is a backup you cannot count on when it matters.
  • Run backup agents and consoles under least privilege. Backup software does not need to be logged in as a domain administrator to do its job, and the backup console has no business facing the public internet. Reducing what the tool can touch reduces what an attacker inherits if they seize it.
  • Patch backup software like the exposed service it is. It is easy to treat backup and security tools as set-and-forget infrastructure. They are software, they have flaws, and – as this week shows – they get exploited. Fold them into the same patch discipline as everything else.
  • Test your restores. None of the above matters if the backups do not actually come back. A backup you have never restored from is a hope, not a plan – which is the whole point of treating your last successful test restore as the real measure of protection.

What this means for your practice

CVE-2026-87886 is a narrow flaw with a wide moral: the tools you trust most – the ones with the deepest access and the most important job – are precisely the ones attackers most want to turn against you. A backup system is only protection if it is itself protected, patched, least-privileged, partly offline, and proven by a real restore. That belongs in your broader downtime and business-continuity plan, not in a folder marked “someone set that up once.” Compudent Systems designs and manages backup for dental practices across the GTA and Ontario with exactly this threat model in mind – immutable and offline copies, hardened and least-privileged agents, patched backup software, and restores we actually test so the safety net is there on the day it is needed. If you are not certain your backups would survive an attack that came looking for them – or you would like a second set of eyes on how your data is protected – contact Compudent for a backup and security assessment. The best time to find out your safety net has a hole in it is not the morning after.


Sources & further reading:

Related Reading



Contact us today - How can we help you?