Critical Vulnerabilities in Plesk and cPanel/WHM
Multiple vulnerabilities, including arbitrary code execution as root, impact various WebPros products including Plesk extensions and cPanel/WHM components.
CVE search metadata
CVE search record: CVE-2026-68492. KEV: no. Product: Plesk (18.0.34 to 18.0.81.0), Plesk RESTful API (2.4.2 to 2.4.6), Site Import (<= 1.12.1), WP Toolkit for cPanel (<= 6.11.2-10794), cPanel/WHM (11.134.0.57, 11.136.0.41, 11.138.0.8). Brief: Critical Vulnerabilities in Plesk and cPanel/WHM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-webpros-vulnerabilities/
CVE search record: CVE-2026-87898. KEV: no. Product: Plesk (18.0.34 to 18.0.81.0), Plesk RESTful API (2.4.2 to 2.4.6), Site Import (<= 1.12.1), WP Toolkit for cPanel (<= 6.11.2-10794), cPanel/WHM (11.134.0.57, 11.136.0.41, 11.138.0.8). Brief: Critical Vulnerabilities in Plesk and cPanel/WHM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-webpros-vulnerabilities/
CVE search record: CVE-2026-87899. KEV: no. Product: Plesk (18.0.34 to 18.0.81.0), Plesk RESTful API (2.4.2 to 2.4.6), Site Import (<= 1.12.1), WP Toolkit for cPanel (<= 6.11.2-10794), cPanel/WHM (11.134.0.57, 11.136.0.41, 11.138.0.8). Brief: Critical Vulnerabilities in Plesk and cPanel/WHM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-webpros-vulnerabilities/
CVE search record: CVE-2026-87900. KEV: no. Product: Plesk (18.0.34 to 18.0.81.0), Plesk RESTful API (2.4.2 to 2.4.6), Site Import (<= 1.12.1), WP Toolkit for cPanel (<= 6.11.2-10794), cPanel/WHM (11.134.0.57, 11.136.0.41, 11.138.0.8). Brief: Critical Vulnerabilities in Plesk and cPanel/WHM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-webpros-vulnerabilities/
WebPros has issued security advisories regarding critical vulnerabilities affecting several of its core hosting management products, including Plesk, its associated extensions, and cPanel/WHM. As of September 23, 2026, researchers and the vendor identified flaws leading to arbitrary code execution (ACE) with root-level privileges.
Specific vulnerabilities include CVE-2026-68492 and CVE-2026-87898, which provide root-level ACE via the 'Plesk RESTful API' and 'Site Import' extensions, respectively. Additionally, cPanel/WHM is impacted by CVE-2026-87899, affecting CalDAV/CardDAV functionality, and CVE-2026-87900, involving improper database creation processes within the WP Toolkit. Given the high-privilege nature of these vulnerabilities and their potential for full system compromise, administrators are urged to verify current versions against the patched releases provided by the vendor.
Impact
Successful exploitation of these vulnerabilities allows an unauthenticated or low-privileged attacker to achieve arbitrary code execution as the root user. This provides full control over the compromised web hosting server, facilitating sensitive data exfiltration, service disruption, and persistence through the installation of backdoors. These vulnerabilities impact a broad range of hosting environments, specifically those utilizing Plesk and cPanel/WHM control panels.
Recommendation
Prioritized actions for administrators include immediate auditing and patching of affected server infrastructure.
- Patch Plesk instances to versions beyond 18.0.81.0 immediately.
- Update 'Plesk RESTful API' extension beyond version 2.4.6.
- Update 'Site Import' extension to versions beyond 1.12.1.
- Update 'WP Toolkit for cPanel' beyond version 6.11.2-10794.
- Update cPanel/WHM to the latest secure versions (11.134.0.57, 11.136.0.41, or 11.138.0.8 depending on the release branch).
Immediate actions
Patch Plesk to 18.0.80.8 or later
Mitigations
Upgrade Plesk to 18.0.80.8 or later
CVE-2026-68492, CVE-2026-87898, CVE-2026-87899, CVE-2026-87900