cPanel disclosed a flaw in its CalDAV and CardDAV service, CVE-2026-87899, that lets any logged-in hosting account run code as root and take full control of the server. It lists no requirement beyond having an account, so on a shared server any customer, or anyone with a stolen customer login, could exploit it. cPanel also fixed a WP Toolkit bug, CVE-2026-87900, letting an account holder alter other accounts' databases, and a third issue, CVE-2026-68490, letting a local user read other accounts' calendars and contacts. Fixes ship across cPanel and WHM version 120 and later branches, including builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 or later, plus WP Toolkit 6.11.3.
Researcher Asim Manizada published working exploit code on September 18 for four Linux kernel local privilege escalation flaws, each letting a local user gain root. The bugs are DirtyAH6 in IPsec AH6, TUNderflow in TUN/TAP, PPPoEject in PPPoE, and DiagSpill in SCTP diagnostics. Kernel maintainers fixed all four in recent weeks after a coordinated hold with distributions, and no in-the-wild abuse has been reported. Three require unprivileged user namespaces, which many distributions enable by default, while DiagSpill needs only an available SCTP module. The exploits are tuned to specific builds and can crash machines, but public code raises risk on shared multi-user systems.
Researchers at Forever Security showed that a single malicious browser extension can hijack the AI assistant built into several AI-enabled browsers, including Chrome, Edge, Comet, Opera Neon, and Claude in Chrome. The core problem is that putting an AI agent inside the browser reopens a privilege-escalation path browsers normally work to close, letting a low-privilege extension reach a high-privilege part of the browser. Two of the findings received identifiers, one in Chrome, patched in January, and one in Edge, patched in July, while the others were fixed through bug bounties without dates. There is no evidence of real-world use yet, and each method still requires the user to install the extension.
Researchers at JFrog disclosed a flaw in Parallels Desktop, which runs Windows and Linux virtual machines on a Mac, that lets a non-administrator user gain root on the Mac itself. Tracked as CVE-2026-90894 and named ParaShells, the issue is that Parallels' root-level background service listens on a socket that was left world-writable, so any program running as a normal user can connect to it and escalate to root. It needs code already running locally, not network access. The fix is in Parallels Desktop 27, but Intel Macs cannot install that version, leaving those users without a patch. Apple-silicon users should update to the latest release on that line.
Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.
LiteSpeed disclosed that versions of its Enterprise web server before 6.3.7 contain a flaw that lets a low-privilege website user gain root access on the underlying server. On shared hosting, that means one tenant, reachable through a cheap plan or a stolen webmail login, can take over the whole machine and every other customer on it. Neither LiteSpeed nor cPanel has published how the flaw works, its severity, a CVE identifier, or whether it has been exploited, leaving defenders with little to hunt for. Because the update may be slow to arrive automatically, administrators are urged to install 6.3.7 manually. LiteSpeed's cPanel plugin had two similar exploited flaws earlier this year.
cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.
Microsoft shipped its largest-ever Patch Tuesday, fixing a record 974 vulnerabilities, including two Windows zero-days already exploited in attacks. Both zero-days are local privilege-escalation flaws that let an attacker gain SYSTEM access: CVE-2026-85880 is a heap buffer overflow in the Advanced Local Procedure Call component that can let code in a low-privilege sandbox escape and elevate, and CVE-2026-81963 is a link-following flaw in the Windows Update Stack. The release also includes about 20 potentially wormable flaws, remotely exploitable without authentication, across services like DNS, DHCP, SMB, and Active Directory, plus critical fixes in Exchange, SharePoint, SQL Server, and Kerberos. The sheer volume makes prioritization essential.
Red Hat disclosed a flaw chain in FreeIPA, the identity-management system that controls logins across Linux domains, that lets a client which never authenticated create an administrator account for itself. The FreeIPA flaw, CVE-2026-76578 and rated 9.8, is an access rule that lets anyone write a one-time-password token without logging in, and does not restrict what else is written alongside it. The second flaw, CVE-2026-76560 in the underlying 389 Directory Server, treats an unauthenticated client's empty name as matching an empty ownership field, so it passes an owner-only check by being nobody. Together they let an anonymous client write a Kerberos identity into the administrators group; a default install is affected.
A researcher known as Chaotic Eclipse, or Nightmare Eclipse, publicly released two unpatched privilege-escalation zero-day exploits targeting security software, without coordinating with the vendors. One, called HardBreacher, targets Kaspersky Endpoint Security and can disrupt the antivirus and its file-access controls while creating a system-level file. The other, PrettyPrague, escapes the Avast sandbox to dump the Windows account database and spawn a SYSTEM-level shell, and reportedly works on fully patched Avast and Windows 11. The researcher suspects it may also affect other Gen Digital products like AVG and Norton. Because there are no CVEs or patches yet, endpoints are exposed, and security tools' high privileges make them valuable targets.