cPanel announced on September 22 that it has patched a critical flaw in its CalDAV and CardDAV service. This vulnerability allowed any user with a cPanel hosting account to execute arbitrary code as root, leading to full control over the server. This poses a significant risk, especially for shared hosting environments where multiple customers share a single server.
A second significant bug was addressed in the WP Toolkit plugin, which is used for installing and managing WordPress sites. This flaw allowed a cPanel account holder to modify databases belonging to other accounts on the same server. While cPanel did not specify the extent of possible modifications or if data could be read, the potential for unauthorized data manipulation is high.
cPanel also fixed a third vulnerability within the same CalDAV and CardDAV service. This flaw permitted a local user on the server to read calendar events and contacts from other accounts. Unlike the root access flaw, this bug did not allow for data modification or root access, limiting its impact to information disclosure.
All three vulnerabilities were discovered and reported by security researcher Ali Mustafa, known as rz1027. Mustafa has been credited with multiple cPanel and Plesk flaws since late August. This series of discoveries highlights ongoing security scrutiny of popular hosting control panels, with previous fixes including a cPanel EmailTrack root code execution flaw and Plesk Backup Manager vulnerabilities.
cPanel has released fixed versions for cPanel & WHM (CVE-2026-87899 and CVE-2026-68490) and the WP Toolkit. Users are advised to follow cPanel's specific update instructions for both cPanel & WHM and the wp-toolkit-cpanel package to mitigate these risks. There is no information available regarding whether the Plesk version of WP Toolkit is affected or if any of these flaws have been actively exploited.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
cPanel released fixes for a critical vulnerability in its CalDAV and CardDAV service that allowed any cPanel account holder to execute code as root, gaining full server control. Additionally, a bug in the WP Toolkit plugin was patched, which permitted account holders to alter databases belonging to other accounts.