cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account

cPanel published three security advisories on September 22. In the most serious, for CVE-2026-87899, the company writes that “an authenticated cPanel account holder can escalate their privileges through cPanel’s CalDAV and CardDAV functionality,” and that successful exploitation “leads to code execution as the root user, giving an attacker full control of the server.” No condition beyond holding an account … Continue reading cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account