Mathew Potter
Security Analyst
cPanel said Tuesday that a calendar service is enough. CVE-2026-87899 sits in CalDAV and CardDAV. Anyone with a hosting account can run code as root and take the whole machine. Full control is their phrase. On a shared box that sells accounts to the public, that is any customer. It is also anyone who stole a customer's login. The Hacker News carried it this morning. We already wrote the Acronis cPanel plugin last week. This is the panel itself.
Three holes, two products. The root one is 87899, cPanel and WHM version 120 and later. A logged-in account, no extra privilege named in the note. Fixed builds: 11.134.0.57 or later, 11.136.0.41 or later, 11.138.0.8 or later, WP Squared 11.138.1.11 or later. The same update covers CVE-2026-68490, a local read of other accounts' calendars and contacts. No write, no root, still a neighbour's address book.
WP Toolkit is separate. CVE-2026-87900 lets a logged-in cPanel user change databases that belong to other accounts. Fixed in Toolkit 6.11.3 or later. The panel upgrade does not move that package for you. cPanel has not said whether the Plesk build of Toolkit is in scope.
No workaround in the advisory. No hunt recipe. Not on CISA's exploited list as of this morning. Ali Mustafa (rz1027) reported all three. He has a pile of cPanel and Plesk credits since late August, including EmailTrack to root on September 8 and Plesk Backup Manager holes on September 10 that could also take the server. The week is the hosting stack, not one CVE.
Plenty of contractor sites, law firms, and small retailers still live on a cPanel share they bought from a reseller. The site looks fine. The calendar sync on a phone is how the account stays "used." If that account can become root, every other tenant on the box is in the blast, including the backups that sit next to the sites. Last week's Acronis plugin (CVE-2026-87886) was already used. This one has no public use in the reporting we have. The lesson is the same: the panel is a computer, and a customer login is enough.
If you are the host, a stolen mailbox password is now a server problem. If you are the tenant, ask the host which build they are on. Do not take "we patch monthly" as an answer this week.
A calendar service that becomes root is not a mail feature. Forensic Five reviews the panel build, who can log in, and whether the copies sit on the same box. From St. Albert, Alberta. Update the trains that have a build. Then go look at the F5 and the WordPress site, because those two also landed overnight.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.