zero-day β€’ SecurityWeek / Acronis

Acronis Patches In-the-Wild Exploited Flaw in cPanel Backup Plugin

Cyber protection software vendor Acronis has issued an urgent security update addressing a vulnerability affecting its official cPanel backup integration plugin following confirmation of active in-the-wild exploitation. The vulnerability allows threat actors to compromise shared web hosting servers, tamper with critical enterprise backup archives, and establish unauthorized privileged footholds across hosting infrastructure.

Acronis Patches In-the-Wild Exploited Flaw in cPanel Backup Plugin

Cyber protection and data recovery solutions provider Acronis has issued an urgent, high-priority security update for its official cPanel backup integration module following verified reports that an undisclosed security vulnerability is facing active in-the-wild exploitation. Widely deployed across thousands of web hosting facilities and cloud service providers globally to orchestrate automated tenant data preservation, the flawed plugin enables attackers to bypass operational boundaries and compromise shared hosting architectures.

cPanel represents the standard management interface across Linux-powered hosting servers. To facilitate granular file restorations and automated MySQL database snapshots, the Acronis cPanel integration operates with elevated system permissions connecting local environments to Acronis Cyber Cloud platforms.

While Acronis has withheld technical vulnerability specifics to protect downstream server operators during patching cycles, cybersecurity news outlet SecurityWeek confirmed that threat actors have actively deployed targeted exploit primitives against exposed hosting management environments. By transmitting crafted requests to the backup integration daemon, adversaries can compromise local directory structures, alter server configurations, and escalate operational execution boundaries.

Threat intelligence analysts emphasize that targeting backup software integrations represents a signature tactic among enterprise ransomware operators (ransomware). Compromising or sabotaging backup pipelines prior to initiating network-wide encryption effectively eliminates the organization's primary recovery capability, severely increasing organizational extortion susceptibility.

Hardening Actions for Hosting Providers and Server Administrators

  • Deploy Plugin Updates Immediately: Execute the official update script via root terminal access:

`/usr/local/cpanel/scripts/update_acronis_plugin` or verify update deployment across the WHM administrative interface.

  • Audit Backup Storage Gateway Integrity: Confirm that existing archived customer snapshots in the Acronis Backup Gateway repository remain untouched and verifiable.
  • Restrict Access to Administrative Consoles: Restrict access to cPanel and WHM management ports (port 2083 and 2087) via dedicated IP allowlisting and require multi-factor authentication (MFA).

Forensic Artifacts and Incident Response Telemetry

Forensic examiners investigating potential web hosting compromise should audit the following system evidence:

1. Audit Acronis Plugin Execution Telemetry: Review diagnostic logs located in `/usr/local/cpanel/logs/acronis/` and `/var/log/acronis/` for abnormal API query strings and unhandled service exceptions. 2. Inspect cPanel User Account Modifications: Cross-reference user authorization profiles in `/var/cpanel/users/` to ensure unauthenticated accounts or API access tokens were not provisioned. 3. Validate File System Permissions on Backup Targets: Confirm local directory ownership and permissions across mounted staging directories to verify unauthorized processes were prevented from modifying archives.

Sources & References

← All News Tools