{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cpanel/whm-11.134.0.57-11.136.0.41-11.138.0.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-68492"},{"id":"CVE-2026-87898"},{"id":"CVE-2026-87899"},{"id":"CVE-2026-87900"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Plesk (18.0.34 to 18.0.81.0)","Plesk RESTful API (2.4.2 to 2.4.6)","Site Import (\u003c= 1.12.1)","WP Toolkit for cPanel (\u003c= 6.11.2-10794)","cPanel/WHM (11.134.0.57, 11.136.0.41, 11.138.0.8)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-hosting","critical-patch"],"_cs_type":"advisory","_cs_vendors":["WebPros"],"content_html":"\u003cp\u003eWebPros has issued security advisories regarding critical vulnerabilities affecting several of its core hosting management products, including Plesk, its associated extensions, and cPanel/WHM. As of September 23, 2026, researchers and the vendor identified flaws leading to arbitrary code execution (ACE) with root-level privileges.\u003c/p\u003e\n\u003cp\u003eSpecific vulnerabilities include CVE-2026-68492 and CVE-2026-87898, which provide root-level ACE via the 'Plesk RESTful API' and 'Site Import' extensions, respectively. Additionally, cPanel/WHM is impacted by CVE-2026-87899, affecting CalDAV/CardDAV functionality, and CVE-2026-87900, involving improper database creation processes within the WP Toolkit. Given the high-privilege nature of these vulnerabilities and their potential for full system compromise, administrators are urged to verify current versions against the patched releases provided by the vendor.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an unauthenticated or low-privileged attacker to achieve arbitrary code execution as the root user. This provides full control over the compromised web hosting server, facilitating sensitive data exfiltration, service disruption, and persistence through the installation of backdoors. These vulnerabilities impact a broad range of hosting environments, specifically those utilizing Plesk and cPanel/WHM control panels.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators include immediate auditing and patching of affected server infrastructure.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Plesk instances to versions beyond 18.0.81.0 immediately.\u003c/li\u003e\n\u003cli\u003eUpdate 'Plesk RESTful API' extension beyond version 2.4.6.\u003c/li\u003e\n\u003cli\u003eUpdate 'Site Import' extension to versions beyond 1.12.1.\u003c/li\u003e\n\u003cli\u003eUpdate 'WP Toolkit for cPanel' beyond version 6.11.2-10794.\u003c/li\u003e\n\u003cli\u003eUpdate cPanel/WHM to the latest secure versions (11.134.0.57, 11.136.0.41, or 11.138.0.8 depending on the release branch).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T19:51:55Z","date_published":"2026-09-24T19:51:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-webpros-vulnerabilities/","summary":"Multiple vulnerabilities, including arbitrary code execution as root, impact various WebPros products including Plesk extensions and cPanel/WHM components.","title":"Critical Vulnerabilities in Plesk and cPanel/WHM","url":"https://feed.craftedsignal.io/briefs/2026-09-webpros-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - CPanel/WHM (11.134.0.57, 11.136.0.41, 11.138.0.8)","version":"https://jsonfeed.org/version/1.1"}