Patch released cPanel & WHM rce WP Toolkit cPanel web-app
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
CVE Tools coverage
cPanel has fixed CVE-2026-87899 in CalDAV and CardDAV, which could allow an authenticated hosting account to execute code as root on cPanel & WHM version 120 and later. The updates also address CVE-2026-68490, exposing other accounts' calendar and contact data, and CVE-2026-87900 in WP Toolkit 6.11.2-10794 and older, which permits cross-account database changes; administrators should update cPanel & WHM to 11.134.0.57, 11.136.0.41, 11.138.0.8, or later, and WP Toolkit to 6.11.3 or later.