Skip to main content
Patch Urgency Is a Vendor Problem, Not YoursVulnerability & Exposure Management
4 min readFor Procurement & Vendor Management Leaders

Patch Urgency Is a Vendor Problem, Not Yours

The conventional wisdom

Every security advisory seems to scream the same message: patch immediately. Drop everything. Schedule emergency maintenance. The CVE-2026-87886 vulnerability in Acronis backup plugins follows this script. Attackers are exploiting it, and Acronis has released updates. Your task: install them now.

Procurement and vendor management practices reinforce this urgency. You're expected to maintain patch SLAs, track vendor response times, and measure your team's speed-to-remediate. When breaches occur, "delayed patching" is often blamed. The implication: you should have acted faster.

This approach unfairly places the burden on your operations team while letting vendors off the hook for shipping exploitable code.

Why this view is incomplete

The "patch faster" narrative addresses symptoms, not causes. It assumes third-party software will have flaws that attackers can exploit, leaving you scrambling to react.

CVE-2026-87886 arises from insecure file permissions in backup plugins connecting cPanel, WebHost Manager, and Plesk deployments to Acronis' cloud. This isn't a zero-day vulnerability; it's a design flaw that slipped through Acronis' security review. Authenticated attackers can escalate privileges with ease. The low attack complexity means exploitation is straightforward.

Focusing solely on patch speed misses three critical questions:

Why did this vulnerability exist? Insecure file permissions are preventable with basic secure development practices. If your vendor can't manage file permissions, what other shortcuts might they have taken?

What's your actual exposure? Acronis notes that exploitation has been detected in limited, targeted attacks against specific configurations. If you don't run these setups, your urgency changes.

What leverage do you have? Your vendor relationship shouldn't be one-sided, where you bear all operational costs of their security failures.

The evidence

Review Acronis' disclosure timeline. They pushed updates last week but haven't shared details about the attacks. You don't know what attackers do post-escalation, the attack vectors, or targeting criteria.

This information gap is common but leaves you in a tough spot. You're expected to assess risk and prioritize remediation without knowing if your environment matches the attacker's target.

The updates are Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 and Acronis Backup extension for Plesk version 1.8.11. Notice the "HF3" designation on the cPanel version, indicating multiple emergency patches.

Your contracts likely mention vendor security practices but probably lack penalties for shipping exploitable code. They don't compensate you for emergency patching costs, business disruptions, or security team overtime.

What to do instead

Shift the cost burden back to vendors during procurement. Your contracts should include:

  • Financial penalties for vulnerabilities exploited within 90 days of disclosure
  • Vendor-funded emergency patching support
  • Mandatory detailed disclosure of exploitation patterns within 72 hours
  • Credits against licensing fees for each critical vulnerability requiring emergency remediation

These aren't punitive; they're about risk allocation. Vendors currently pass security costs onto your operations budget. Change that.

Incorporate vendor security posture into your risk register. Don't treat all third-party software equally. Acronis serves web hosting providers and managed service providers, meaning a vulnerability can affect multiple customer environments. Track this concentration risk separately from your standard vendor inventory.

Create tiered patch response protocols based on your configuration. CVE-2026-87886 affects specific backup plugins. If you don't use cPanel, WHM, or Plesk, or if you use different solutions, adjust your response timeline accordingly. Document your configuration baseline and filter security advisories.

Demand architectural accountability. Insecure file permissions suggest deeper issues with the vendor's development lifecycle. Your vendor review should include questions about:

  • Secure coding standards
  • Pre-release security testing
  • Third-party security audits
  • Mean time between critical vulnerabilities

If a vendor can't provide specifics, that's a procurement red flag.

When the conventional wisdom is right

Patch urgency matters when you're running the affected configuration and the vulnerability threatens business-critical systems. If you're a hosting provider using Acronis backup plugins for cPanel & WHM, prioritize this. The low attack complexity and confirmed exploitation make it a genuine emergency.

If you lack visibility into your third-party plugin inventory, assume exposure until proven otherwise. This justifies urgent action.

The conventional wisdom also holds with strong vendor relationships that include transparent disclosure and support. Some vendors provide detailed intelligence, offer assisted patching, and take financial responsibility for security failures. These partnerships justify faster response because the vendor shares the burden.

But if your vendor treats you as a cost center, and your contract lets them pass all security risk onto your team, then "patch immediately" isn't a strategy. It's costly theater that ignores the root problem.

The Acronis vulnerability should prompt two actions: patch if you're exposed, and renegotiate if you're tired of bearing your vendors' security debt.

You Might Also Like