Acronis Plugin Security Advisory (SEC-10986) -cPanel/Plesk

Incident Report for Liquid Web - Services

Monitoring

The security patch for CVE-2026-87886 (SEC-10986) is applied across the affected Acronis Cyber Protect Backup plugins.

Our Engineering team continues to monitor the environment and validate the patched systems. We have not observed any new issues since our last update.

If you need assistance or have any concerns, please get in touch with our Support team.
Posted Sep 17, 2026 - 06:09 EDT

Update

The security patch for CVE-2026-87886 (SEC-10986) is being applied across the affected Acronis Cyber Protect Backup plugin.

Our engineers continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update run.

We will provide further updates as needed. Thank you for your patience and understanding.
Posted Sep 17, 2026 - 01:25 EDT

Identified

We are aware of the recent security advisory (SEC-10986) regarding the Acronis Cyber Protect Backup plugin for hosting control panels (cPanel/Plesk).

Our Engineers are actively evaluating the impact across our fleet and verifying plugin versioning. We are conducting a thorough audit to confirm full patch coverage, identify any edge cases that require manual updates, and ensure that all managed systems remain secure.

Service Disruption: None. Backups and control panel operations remain fully functional.

We are actively auditing server inventory alongside our engineering teams. Further updates will be provided as soon as the fleet-wide verification is complete
Posted Sep 16, 2026 - 10:49 EDT
This incident affects: CPanel and Plesk.