Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical cPanel Vulnerabilities Allow Root Access and Server Control

Critical cPanel Vulnerabilities Allow Root Access and Server Control

Posted on September 23, 2026 By CWS

Recent vulnerabilities discovered in cPanel’s services have exposed significant security risks, allowing users with hosting accounts to gain root access and control over the entire server. These issues were acknowledged by cPanel on September 22, 2026, highlighting the urgency for users to update their systems.

Details of the cPanel Exploits

A primary flaw identified in the CalDAV and CardDAV services enables a hosting account holder to execute code with root privileges, potentially compromising server integrity. This issue does not require additional permissions beyond holding an account on a shared server, making it accessible to many users.

Additionally, a vulnerability within the WP Toolkit plugin compromises database integrity by allowing unauthorized access to alter databases associated with other accounts. This flaw primarily affects versions up to WP Toolkit 6.11.2-10794.

Patches and Fixes Released

cPanel has addressed these vulnerabilities by releasing updated versions of their services. The critical CalDAV and CardDAV issue is resolved in cPanel & WHM versions 11.134.0.57, 11.136.0.41, and 11.138.0.8, among others. For the WP Toolkit bug, users are advised to upgrade to version 6.11.3 or later to ensure their systems are secure.

While no temporary workarounds have been provided for those unable to update immediately, cPanel recommends users follow their detailed update instructions to mitigate these risks effectively.

Implications and Security Recommendations

The discovery of these vulnerabilities underscores the critical need for regular system updates and vigilance in server management. cPanel has credited researcher Ali Mustafa, known as rz1027, for uncovering these flaws, further emphasizing the importance of collaboration between security researchers and software providers.

Operators using both cPanel and Plesk, another control panel from the same parent company, should remain alert for updates, as similar vulnerabilities may exist across platforms.

As the landscape of web security continues to evolve, staying informed and proactive about potential threats is essential for maintaining robust server defenses.

For those managing affected systems, immediate updates are crucial. Follow cPanel’s guidance for upgrading cPanel & WHM and WP Toolkit to the latest versions to protect against unauthorized access and potential data breaches.

The Hacker News Tags:CalDAV, CardDAV, cPanel, Hosting, root access, Security, Server, Vulnerabilities, WP Toolkit

Post navigation

Previous Post: SolarWinds Vulnerabilities Enable Remote Code Execution
Next Post: AI Adoption in OT Security Grows, Full Autonomy Still Uncommon

Related Posts

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants The Hacker News
EC-Council Boosts AI Workforce with New Certifications EC-Council Boosts AI Workforce with New Certifications The Hacker News
Enhancing Mobile Security with Samsung Knox Enhancing Mobile Security with Samsung Knox The Hacker News
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads The Hacker News
Insights from 160 Million Attack Simulations Insights from 160 Million Attack Simulations The Hacker News
EtherRAT Uses GitHub Facades to Target Admin Accounts EtherRAT Uses GitHub Facades to Target Admin Accounts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Persistent Malware Infrastructure Despite Domain Changes
  • AI Adoption in OT Security Grows, Full Autonomy Still Uncommon
  • Critical cPanel Vulnerabilities Allow Root Access and Server Control
  • SolarWinds Vulnerabilities Enable Remote Code Execution
  • Adobe Issues Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Persistent Malware Infrastructure Despite Domain Changes
  • AI Adoption in OT Security Grows, Full Autonomy Still Uncommon
  • Critical cPanel Vulnerabilities Allow Root Access and Server Control
  • SolarWinds Vulnerabilities Enable Remote Code Execution
  • Adobe Issues Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark