The Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting a Roundcube Webmail flaw, CVE-2026-48842, four months after it was patched. Roundcube is a browser-based IMAP client used as the default mail interface by thousands of services and pre-installed with the cPanel hosting control panel. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that handles database-driven user lookups. Exploitation lets an unprivileged attacker bypass authentication, inject and run database commands, and steal data from Roundcube's database, without user interaction in high-complexity attacks. Roundcube fixed it in versions 1.6.16 and 1.7.1, and Shadowserver tracks over 523,000 exposed instances online.
cPanel disclosed a flaw in its CalDAV and CardDAV service, CVE-2026-87899, that lets any logged-in hosting account run code as root and take full control of the server. It lists no requirement beyond having an account, so on a shared server any customer, or anyone with a stolen customer login, could exploit it. cPanel also fixed a WP Toolkit bug, CVE-2026-87900, letting an account holder alter other accounts' databases, and a third issue, CVE-2026-68490, letting a local user read other accounts' calendars and contacts. Fixes ship across cPanel and WHM version 120 and later branches, including builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 or later, plus WP Toolkit 6.11.3.
Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.
cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.
A critical flaw in cPanel and WHM, the dominant web hosting control panel, lets a low-privilege but authenticated account take root control of an entire server. Tracked as CVE-2026-65643, the bug lives in the domain-parking feature, which is enabled in virtually every shared and reseller hosting environment. Any account allowed to add parked or addon domains can create arbitrary files anywhere on the underlying server, leading to code execution as root. No advanced skills or chained bugs are needed, only a legitimate low-tier login obtainable through a cheap hosting plan or a compromised account. On shared hosting, one such account can compromise every site, database, and mailbox on the box.
cPanel patched a critical flaw that lets an ordinary hosting customer escalate to full database administrator access, running SQL as the database root user. Tracked as CVE-2026-58048 with a score of 9.4, the bug is significant on shared hosting, where many customers use one database server: administrator access there can expose or alter other tenants' data, and depending on the operating system and database configuration, cPanel warns it may extend to operating-system-level compromise. cPanel is one of the most widely deployed web hosting control panels, so the flaw affects a large number of shared and reseller hosting environments. Fixes shipped across several release tiers.
CISA has added a LiteSpeed cPanel plugin flaw to its known-exploited list and given federal agencies until June 18 to patch. The bug (CVE-2026-54420, rated 8.5) lets a user who already has FTP or web-shell access on a shared hosting server escalate to root by abusing how the plugin follows symbolic links, on servers running CloudLinux or CageFS. On multi-tenant hosting that turns one compromised account into full control of the whole server and every site on it. Namecheap reported it after spotting suspicious activity, and LiteSpeed flagged active exploitation in early June. The fix is LiteSpeed WHM Plugin 5.3.2.1 with cPanel plugin 2.4.8.
LiteSpeed Technologies has patched CVE-2026-48172, a privilege-escalation vulnerability in its cPanel plugin that lets a low-privileged cPanel user trick the plugin into running scripts as root. The flaw has been observed under active exploitation. The fix lands in cPanel plugin v2.4.7 bundled with WHM plugin 5.3.1.0. Operators who cannot patch immediately are advised to uninstall the user-end plugin via /usr/local/lsws/admin/misc/lscmctl cpanelplugin --uninstall. This follows last month's actively exploited CVE-2026-41940 (CVSS 9.8) in cPanel itself, which threat actors used to drop Mirai variants and the Sorry ransomware strain. cPanel hosting providers and resellers are the primary targets.
QiAnXin XLab has tied the ongoing exploitation of cPanel's CVE-2026-41940 to a previously-quiet threat actor it tracks as Mr_Rot13, who has been operating since at least 2020. The attack chain exploits the cPanel and WHM authentication bypass to drop a Go-based infector that adds an attacker SSH key, plants a PHP web shell, and serves a fake login page to steal cPanel credentials (ROT13-encoded, exfiltrated to wrned[.]com). The final payload is a cross-platform backdoor called Filemanager that runs on Windows, macOS, and Linux. XLab counts over 2,000 attacker source IPs currently scanning for this flaw.
cPanel released patches Friday for three new vulnerabilities. The two worst (CVE-2026-29202 and CVE-2026-29203, both CVSS 8.8) let authenticated users execute arbitrary Perl code through the create_user API or escalate privileges via unsafe symlink chmod. The third (CVE-2026-29201, CVSS 4.3) lets authenticated users read arbitrary files. No exploitation observed yet. The disclosure lands while attackers are still mass-exploiting CVE-2026-41940 to deploy 'Sorry' ransomware against cPanel hosts, including a wave targeting government agencies and MSPs (covered May 5). Hosting providers face a compounding patch burden.