Liquid Web incident
Acronis Plugin Security Advisory (SEC-10986) -cPanel/Plesk
Liquid Web experienced a minor incident on September 16, 2026 affecting CPanel and Plesk, lasting 2d 11h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- identified Sep 16, 2026, 02:49 PM UTC
We are aware of the recent security advisory (SEC-10986) regarding the Acronis Cyber Protect Backup plugin for hosting control panels (cPanel/Plesk). Our Engineers are actively evaluating the impact across our fleet and verifying plugin versioning. We are conducting a thorough audit to confirm full patch coverage, identify any edge cases that require manual updates, and ensure that all managed systems remain secure. Service Disruption: None. Backups and control panel operations remain fully functional. We are actively auditing server inventory alongside our engineering teams. Further updates will be provided as soon as the fleet-wide verification is complete
- identified Sep 17, 2026, 05:25 AM UTC
The security patch for CVE-2026-87886 (SEC-10986) is being applied across the affected Acronis Cyber Protect Backup plugin. Our engineers continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update run. We will provide further updates as needed. Thank you for your patience and understanding.
- monitoring Sep 17, 2026, 10:09 AM UTC
The security patch for CVE-2026-87886 (SEC-10986) is applied across the affected Acronis Cyber Protect Backup plugins. Our Engineering team continues to monitor the environment and validate the patched systems. We have not observed any new issues since our last update. If you need assistance or have any concerns, please get in touch with our Support team.
- resolved Sep 19, 2026, 02:15 AM UTC
This incident has been resolved.