Executive Summary
In September 2026, cPanel disclosed three critical vulnerabilities affecting its hosting control panel software used by millions of websites worldwide. CVE-2026-87899, the most severe flaw, allows any hosting account holder to execute code as root through the CalDAV/CardDAV service, enabling complete server takeover. CVE-2026-87900 permits unauthorized database modifications across accounts via the WP Toolkit plugin, while CVE-2026-68490 enables reading other users' calendar and contact data. These vulnerabilities affect cPanel versions 120 and later, with fixes released across multiple version branches.
These vulnerabilities highlight the growing threat to shared hosting infrastructure, where a single compromised account can lead to full server compromise affecting hundreds or thousands of websites. The timing coincides with increased scrutiny of web hosting security following recent supply chain attacks and the rise in ransomware targeting hosting providers.
Why This Matters Now
Shared hosting environments are under increased attack as threat actors seek to maximize impact through single compromise points. With cPanel powering over 70% of shared hosting globally, these privilege escalation flaws represent a critical threat vector for mass website compromises and ransomware deployment.
Attack Path Analysis
Attackers exploited cPanel CalDAV/CardDAV vulnerabilities (CVE-2026-87899) to gain initial access to hosting accounts, then escalated privileges to root access for full server control. With root privileges, they moved laterally across shared hosting environments, established command and control through compromised hosting infrastructure, exfiltrated sensitive customer data and databases, and caused widespread service disruption by compromising multiple customer accounts on shared hosting platforms.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-87899 in cPanel's CalDAV and CardDAV service, requiring only a valid hosting account to execute the vulnerability
Related CVEs
CVE-2026-87899
CVSS 8.8A privilege escalation vulnerability in cPanel's CalDAV and CardDAV service allows a logged-in account holder to execute code as root and gain full server control.
Affected Products:
cPanel cPanel & WHM – 120.0 to 11.134.0.56, 11.136.0.0 to 11.136.0.40, 11.138.0.0 to 11.138.0.7
Exploit Status:
no public exploitCVE-2026-87900
CVSS 6.5A vulnerability in WP Toolkit plugin allows a logged-in cPanel user to perform database modifications in other accounts.
Affected Products:
WebPros WP Toolkit – 6.11.2-10794 and older
Exploit Status:
no public exploitCVE-2026-68490
CVSS 4.3An information disclosure vulnerability in cPanel's CalDAV and CardDAV functionality allows a local user to read other accounts' calendar events and contacts.
Affected Products:
cPanel cPanel & WHM – 120.0 to 11.134.0.56, 11.136.0.0 to 11.136.0.40, 11.138.0.0 to 11.138.0.7
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Exploitation for Privilege Escalation
Exploit Public-Facing Application
Sudo and Sudo Caching
Container and Resource Discovery
Domain Policy Modification
Data from Local System
Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software vulnerabilities are addressed
Control ID: 6.2.4
CISA Zero Trust Maturity Model 2.0 – Software platforms are inventoried
Control ID: ID.AM-2
DORA – ICT third-party risk
Control ID: Article 11
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.10
ISO 27001:2022 – Use of privileged utility programs
Control ID: 8.24
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Internet
Web hosting providers face critical privilege escalation risks allowing customer account holders to gain root server control through cPanel vulnerabilities.
Information Technology/IT
IT service providers using cPanel hosting infrastructure vulnerable to customer-initiated privilege escalation attacks compromising entire server environments and client data.
Computer Software/Engineering
Software companies relying on shared cPanel hosting face unauthorized database access risks and potential intellectual property theft through WordPress Toolkit vulnerabilities.
E-Learning
Educational platforms on cPanel hosting vulnerable to cross-account data breaches affecting student records and calendar information through CalDAV/CardDAV flaws.
Sources
- New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Controlhttps://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.htmlVerified
- Security CVE-2026-87899 Vulnerability in cPanel's CalDAV/CardDAV - September 22, 2026https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026Verified
- Security CVE-2026-87900 Vulnerability in WP Toolkit Database Creation - September 22, 2026https://support.cpanel.net/hc/en-us/articles/43597969409943-Security-CVE-2026-87900-Vulnerability-in-WP-Toolkit-Database-Creation-September-22-2026Verified
- Security CVE-2026-68490 Vulnerability in cPanel's CalDAV/CardDAV Functionality - September 22, 2026https://support.cpanel.net/hc/en-us/articles/43502940099991-Security-CVE-2026-68490-Vulnerability-in-cPanel-s-CalDAV-CardDAV-Functionality-September-22-2026Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this cPanel vulnerability exploitation by implementing microsegmentation and identity-aware access controls across the shared hosting infrastructure. The segmented architecture would likely have reduced the blast radius from full server compromise to isolated workload exposure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Microsegmentation would likely have isolated the compromised CalDAV/CardDAV service from critical hosting infrastructure, constraining the attacker's ability to leverage the vulnerability for broader system access beyond the specific workload boundary.
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely have constrained privilege escalation by enforcing least-privilege principles and limiting service account permissions, potentially reducing the attacker's ability to achieve unrestricted root access across the entire hosting platform.
Control: East-West Traffic Security
Mitigation: Network microsegmentation would likely have blocked unauthorized lateral movement between customer accounts by enforcing strict east-west traffic policies, constraining the attacker's ability to traverse the shared hosting infrastructure and access multiple tenant environments.
Control: Multicloud Visibility & Control
Mitigation: Comprehensive traffic visibility and behavioral monitoring would likely have detected anomalous command and control patterns, constraining the attacker's ability to maintain persistent access through unauthorized communication channels within the hosting infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have limited unauthorized data exfiltration by enforcing strict outbound traffic controls and data loss prevention rules, constraining the attacker's ability to extract large volumes of customer data through unrestricted network paths.
Residual impact would likely be constrained to specific isolated workload segments rather than full hosting platform compromise, limiting the scope of affected customer accounts and reducing the overall blast radius of the security incident.
Impact at a Glance
Affected Business Functions
- Web Hosting Services
- Server Management
- Customer Account Management
- WordPress Site Management
Estimated downtime: 2 days
Estimated loss: N/A
Potential exposure of customer calendar events, contacts, and database contents across multiple hosting accounts on affected shared servers. Full server compromise could lead to exposure of all hosted customer data including websites, databases, and email accounts.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent privilege escalation from standard user accounts to root access, enforcing least privilege principles across hosting environments
- • Deploy Inline IPS (Suricata) with updated signatures to detect and block exploitation attempts targeting known CVEs like CVE-2026-87899 before they can execute
- • Enable Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns that could indicate vulnerability exploitation
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from compromised hosting accounts and detect suspicious outbound traffic
- • Deploy Cloud Native Security Fabric (CNSF) with real-time inspection capabilities to autonomously detect and respond to privilege escalation attempts and cross-account access violations



