Find notable cyber news and cases, enriched with sources, timelines, and signals.

CPanel CalDAV and CardDAV root code execution security flaw (CVE-2026-87899)

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

cPanel's fix for CVE-2026-87899 closes a CalDAV and CardDAV flaw that let a logged-in hosting account run code as root, putting affected servers at risk of full control. The issue affected cPanel & WHM and WP Squared, and cPanel released patched builds for the supported release lines. No temporary workaround was offered, so exposed systems need an update to remove the risk.

Related Happenings

CPanel CalDAV and CardDAV calendar/contact read flaw (CVE-2026-68490)

Vulnerability
H score27 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

How related: That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access.

About this happening: cPanel fixed CVE-2026-68490, a CalDAV and CardDAV flaw that lets a local user read other accounts' calendar events and contacts on affected hosting systems. The bu...

WP Toolkit cross-account database modification security flaw (CVE-2026-87900)

Vulnerability
H score1 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

How related: A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.

About this happening: The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting system...

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

CPanel CVE-2026-41940 mitigation guidance

Advisory/Mitigation
H score89 First: 30.04.2026 14:40 Last: 30.04.2026 14:40 Sources 1

About this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...

Timeline

  1. 23.09.2026 15:16 2 articles · 2h ago

    cPanel discloses CalDAV and CardDAV root code execution flaw

    Initial Disclosure

    cPanel said on September 22, 2026 that CVE-2026-87899 in its CalDAV and CardDAV service lets a logged-in cPanel hosting account run code as root and take full control of the server, with account access as the only stated requirement for the flaw.

    Show sources
  2. 23.09.2026 15:16 1 articles · 2h ago

    cPanel releases fixed builds for CalDAV and CardDAV root flaw

    Mitigation Patch Update

    cPanel released fixed builds for CVE-2026-87899 in cPanel & WHM 11.134.0.57, 11.136.0.41, and 11.138.0.8, and in WP Squared 11.138.1.11, while also stating that the update repairs calendar and contact permissions for existing accounts and that no temporary workaround is available.

    Show sources