"full control of the server," cPanel warned on September 22, describing a flaw that lets any cPanel hosting account run code as root.
What cPanel disclosed on September 22
cPanel published advisories on September 22 for three separate flaws affecting its hosting control panel and an add-on plugin. The most urgent, in the CalDAV and CardDAV service, "lets anyone with a cPanel hosting account run code as root and take 'full control of the server,'" the company said. A second bug in the WP Toolkit plugin permits a logged-in cPanel user to "perform database modifications in other accounts." A third flaw in the same calendar-and-contacts service lets a local user on the server read other accounts' calendar events and contacts but not change them or achieve root access.
The tracked CVEs and fixed releases
- cPanel & WHM: CVE-2026-87899 and CVE-2026-68490 — cPanel instructs administrators to update using WHM's "Upgrade to Latest Version" or by running /usr/local/cpanel/scripts/upcp --force as root. The update also repairs calendar and contact permissions for existing accounts.
- WP Toolkit: CVE-2026-87900 — the WP Toolkit package (wp-toolkit-cpanel) must be updated to version 6.11.3 or later. cPanel published this installer command: bash <(curl https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -O - https://wp-toolkit.plesk.com/cPanel/installer.sh) --version 6.11.3.
- Calendar/contact flaws: these affect CalDAV/CardDAV in version 120 and later; cPanel listed fixed builds for the 134, 136, and 138 release lines and for WP Squared.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScope of risk: who can exploit these bugs
cPanel's advisory states the root-escalation flaw requires only "having an account." On shared servers where hosting providers sell accounts to the public, that means any paying customer could exploit it — and so could anyone who obtains a customer's login credentials. The WP Toolkit issue, cPanel says, allows a logged-in cPanel user to modify databases owned by other accounts; the vendor does not say what specific changes are possible, whether data from other accounts can be read, or whether the user needs direct access to WP Toolkit itself.
What the record shows about active exploitation and related fixes
None of the three advisories mentions public reports of exploitation, nor do they provide a method to detect whether a server was compromised before updating. When The Hacker News checked on September 23, none of the three flaws appeared in CISA's Known Exploited Vulnerabilities catalog. cPanel credited researcher Ali Mustafa (rz1027) with discovering all three defects; vendor advisories and CVE records credit him with at least seven cPanel and Plesk flaws disclosed since August 27, three of them shared with a researcher known as abed1526. cPanel's recent disclosures also include a September 8 flaw in the EmailTrack feature that allowed an account with mail privileges to run code as root, and Plesk fixes on September 10 for Backup Manager issues that could let a customer take over the whole server.
How to update now — exact commands and limitations
cPanel provides distinct update procedures:
- To update cPanel & WHM (addressing CVE-2026-87899 and CVE-2026-68490): use WHM's Home / cPanel / Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root. This update also corrects calendar and contact permissions for existing accounts.
- To update WP Toolkit (CVE-2026-87900): run the installer command above to reach version 6.11.3 or later.
cPanel explicitly offers no temporary workaround for servers that cannot be updated immediately. For WP Toolkit, the vendor provided only the manual installer command and did not state whether automatic updates will install 6.11.3.
What this means for hosting providers, cPanel account holders, and security teams
- Hosting providers should prioritize rolling the cPanel & WHM updates to customer-facing shared servers because cPanel lists no preconditions for root escalation other than an account—meaning any customer account could be a launching point for full-server takeover.
- cPanel account holders must update WP Toolkit to version 6.11.3 or later if they use the wp-toolkit-cpanel package; they should also ensure their providers have applied the WHM updates. Because cPanel says anyone with an account — or anyone who obtains account credentials — could exploit the CalDAV/CardDAV flaw, account credential hygiene is a material risk factor.
- Security teams and incident responders should note that cPanel's advisories do not include indicators of compromise or retrospective detection steps; organizations that cannot immediately apply updates will have no vendor-supplied temporary mitigations to fall back on.
cPanel's fixes close a cluster of recent, similar issues but leave two clear operational questions: whether Plesk's WP Toolkit is affected (cPanel has not said), and how providers will mitigate risk where immediate patching is impractical. For administrators and customers on shared systems, the simplest immediate action is to verify updates were applied; for everyone else, the record here is a reminder that a single account on a shared platform can, according to the vendor, be all an attacker needs.




