{"id":1941,"date":"2026-09-24T12:05:41","date_gmt":"2026-09-24T06:35:41","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1941"},"modified":"2026-09-25T10:20:50","modified_gmt":"2026-09-25T04:50:50","slug":"cpanel-cve-2026-87899-root-server-control","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/","title":{"rendered":"cPanel CVE-2026-87899: Root Code Execution and Shared Hosting Risk"},"content":{"rendered":"<p>Sharing a hosting server should not mean sharing access to another company\u2019s systems. On September 22, 2026, cPanel disclosed cPanel CVE-2026-87899, which lets an authenticated account escalate privileges through its calendar and contact functionality.<\/p>\n<p>Successful exploitation can give an attacker server-wide control. The disclosure therefore matters to hosting providers, MSPs, and businesses that rely on hosted websites and applications.<\/p>\n<p>The immediate priority is confirming updates. However, teams should also understand the separate database and data-access flaws disclosed alongside it.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is cPanel?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tcPanel provides web hosting management software. Its cPanel interface lets account holders manage resources such as websites, email, files, and databases. WebHost Manager, or WHM, provides administrative functions for managing hosting accounts and servers.<\/p>\n<p>In shared hosting, multiple customers use resources on the same underlying server. Account permissions help separate their environments, while server administrators hold broader privileges. That distinction makes vulnerabilities crossing account boundaries particularly important.<\/p>\n<p>WP Toolkit adds WordPress management capabilities to this environment. CalDAV and CardDAV support calendar and contact functions. The disclosures concern these hosting components; they do not identify a named threat group. Hosting providers generally handle server updates, while customers should verify remediation with their provider.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<p>The September 22 disclosures describe three distinct vulnerabilities. They should not be treated as a confirmed multi-stage attack chain.<\/p>\n<table>\n<thead>\n<tr>\n<th>Vulnerability<\/th>\n<th>Required access<\/th>\n<th>Disclosed impact<\/th>\n<th>Affected versions<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2026-87899<\/td>\n<td>Authenticated cPanel account<\/td>\n<td>Code execution as root through CalDAV\/CardDAV<\/td>\n<td>cPanel &amp; WHM v120 onward, before the applicable fix<\/td>\n<\/tr>\n<tr>\n<td>WP Toolkit CVE-2026-87900<\/td>\n<td>Authenticated cPanel user<\/td>\n<td>Database modifications in other accounts<\/td>\n<td>WP Toolkit 6.11.2-10794 and earlier<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-68490<\/td>\n<td>Local user on the same server<\/td>\n<td>Reading other accounts\u2019 calendar events and contacts<\/td>\n<td>cPanel &amp; WHM v120 onward, before the applicable fix<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The calendar permissions flaw does not grant root access or permission to modify the exposed data. Its update corrects permissions for new storage and repairs existing accounts.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/msp-ready-uem-platform.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 7 Features to Look for in an MSP-Ready UEM Platform<\/h4><p>Explore seven essential features of an MSP-ready UEM platform for secure, scalable client management.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-7-features-to-look-for-in-an-msp-ready-uem-platform\/\" aria-label=\"Top 7 Features to Look for in an MSP-Ready UEM Platform\"><\/a><\/div><\/div><\/div><\/p>\n<h3>Which versions contain fixes?<\/h3>\n<p>For the two CalDAV\/CardDAV issues, patched builds include <strong>134.0.57<\/strong>, <strong>136.0.41<\/strong>, and <strong>138.0.8<\/strong>, or later builds in their respective release lines. The listed WP Squared fix is <strong>138.1.11<\/strong> or later. These versions omit the leading \u201c11.\u201d used in the advisories.<\/p>\n<p>For WP Toolkit, update to <strong>6.11.3 or later<\/strong>. Check its installed version separately rather than assuming the main control-panel update covers it.<\/p>\n<p>The advisories direct administrators to update and do not document a temporary workaround.<\/p>\n<h3>What remains uncertain?<\/h3>\n<p>The advisories do not identify an attacker, victim organization, initial credential-theft method, persistence technique, or ransomware activity. They also do not establish active exploitation.<\/p>\n<p>An attacker could potentially use a compromised hosting account, but credential theft is not a confirmed part of these disclosures. A malicious account holder could also satisfy the authentication requirement. No MFA bypass should be inferred.<\/p>\n<h2>Why this matters<\/h2>\n<p>Shared hosting security depends on keeping one customer\u2019s permissions separate from another\u2019s. A privilege-escalation flaw can undermine that separation even when the affected business maintains its own website carefully.<\/p>\n<p>Potential consequences include unauthorized changes, exposure of server-accessible secrets, and disruption across hosted services. These are possible outcomes, not confirmed losses from this disclosure.<\/p>\n<p>MFA can reduce some account-takeover risks, but it cannot repair a vulnerability available to an authenticated user. Similarly, securing an administrator\u2019s laptop does not remove a flaw inside the hosting platform.<\/p>\n<p>Effective MSP security therefore needs several layers: verified server updates, limited administrative access, protected administrator devices, and an investigation process. Where evidence suggests web hosting compromise, responders should assess the server and neighboring accounts rather than checking only one website.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-IDP_Usecases\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-IDP_Usecases\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode IdP use cases\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Check out this document for a quick glance into Hexnode IdP's capabilities.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/hexnode-idp-use-cases\/'>\n                            Get the infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode can help<\/h2>\n<p>Hexnode can strengthen administrator endpoints and support response to related endpoint threats. Remediation of the hosting vulnerabilities remains a server-management responsibility.<\/p>\n<h3>Hexnode UEM: Check administrator-device compliance<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> supports configurable compliance checks, including supported operating-system, encryption, and application criteria. Teams can use these checks to identify administrator devices that fall outside their security requirements.<br \/>\nApply suitable policies to devices used for hosting administration and investigate compliance failures. This helps maintain the surrounding administrative environment, but device compliance does not verify a cPanel patch or prevent a malicious hosting customer from exploiting an unpatched server.<\/p>\n<h3>Hexnode UEM: Support device-aware access decisions<\/h3>\n<p>Hexnode\u2019s Microsoft Entra Conditional Access integration lets supported device-compliance information inform access policies for integrated resources. Microsoft Entra enforces the configured access decision.<\/p>\n<p>By default, cPanel\/WHM authenticates users through local accounts on the Linux hosting server. Hexnode UEM\u2019s integration does not automatically extend Conditional Access to these native logins. Access to the management console must pass through Microsoft Entra authentication\u2014for example, through Entra Application Proxy with Entra preauthentication or a supported, configured federated single sign-on (SSO) integration. Direct login paths must also be restricted to prevent users from bypassing that access policy.<\/p>\n<p>Use this where the administrative resource, device platform, and integration support the intended policy. Do not assume this automatically protects direct cPanel or WHM logins. Validate the access path and relevant licensing before relying on compliance-gated access.<\/p>\n<h3>Hexnode XDR: Investigate and contain affected endpoints<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> secures Windows and macOS administrator workstations, helping teams investigate signs of credential theft or endpoint malware. Its role here is to protect those workstations, rather than operate on the Linux hosting server itself. It supports endpoint investigation and response actions, including device isolation and process termination. These capabilities can help when an investigation finds malicious processes or other supported threat signals on an administrator endpoint.<\/p>\n<p>An XDR investigation can complement server-side analysis if evidence links endpoint activity to the incident. However, endpoint telemetry alone cannot confirm whether someone exploited the cPanel service. Server logs, account activity, and forensic evidence remain necessary.<\/p>\n<h2>What security teams should do next<\/h2>\n<p>Treat cPanel root code execution as a server-remediation priority. An update closes the vulnerability, but it does not establish whether earlier compromise occurred.<\/p>\n<ol>\n<li><strong>Verify installed versions.<\/strong> Inventory affected servers, apply the correct patched build, and check WP Toolkit separately. Shared-hosting customers should request confirmation from their provider.<\/li>\n<li><strong>Review access.<\/strong> Remove unnecessary accounts and privileges. Restrict administrative routes and enforce appropriate authentication controls.<\/li>\n<li><strong>Investigate suspicious activity.<\/strong> Preserve logs and examine unexplained privileged actions, cross-account changes, unfamiliar scheduled tasks, and unauthorized access keys. These are investigation leads, not published indicators specific to these flaws.<\/li>\n<li><strong>Respond to confirmed exposure.<\/strong> Contain affected systems and rotate exposed credentials or keys from trusted devices. Follow incident-response procedures if server integrity is uncertain.<\/li>\n<li><strong>Strengthen administrator endpoints.<\/strong> Apply suitable compliance requirements through Hexnode UEM and use Hexnode XDR for relevant endpoint investigation and containment.<\/li>\n<\/ol>\n<p>Close remediation only after verifying updates and resolving suspicious findings.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f<\/h5><p>Sign up for Hexnode to strengthen administrator-device compliance and support endpoint threat response.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sharing a hosting server should not mean sharing access to another company\u2019s systems. On September&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1961,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[19,21],"class_list":["post-1941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-and-saas","category-patch-management","product_category-unified-endpoint-management","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>cPanel CVE-2026-87899: Root Access Risk and Fixes<\/title>\n<meta name=\"description\" content=\"cPanel patched CVE-2026-87899, allowing a hosting account to execute code as root and potentially control a server.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"cPanel CVE-2026-87899: Root Access Risk and Fixes\" \/>\n<meta property=\"og:description\" content=\"cPanel patched CVE-2026-87899, allowing a hosting account to execute code as root and potentially control a server.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T06:35:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-25T04:50:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cPanel-CVE-2026-87899.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"cPanel CVE-2026-87899: Root Code Execution and Shared Hosting Risk\",\"datePublished\":\"2026-09-24T06:35:41+00:00\",\"dateModified\":\"2026-09-25T04:50:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/\"},\"wordCount\":1102,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cPanel-CVE-2026-87899.png?format=webp\",\"articleSection\":[\"Cloud and SaaS\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/\",\"name\":\"cPanel CVE-2026-87899: Root Access Risk and Fixes\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cPanel-CVE-2026-87899.png?format=webp\",\"datePublished\":\"2026-09-24T06:35:41+00:00\",\"dateModified\":\"2026-09-25T04:50:50+00:00\",\"description\":\"cPanel patched CVE-2026-87899, allowing a hosting account to execute code as root and potentially control a server.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cPanel-CVE-2026-87899.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cPanel-CVE-2026-87899.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"cPanel CVE-2026-87899\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cpanel-cve-2026-87899-root-server-control\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"cPanel CVE-2026-87899: Root Code Execution and Shared Hosting Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"cPanel CVE-2026-87899: Root Access Risk and Fixes","description":"cPanel patched CVE-2026-87899, allowing a hosting account to execute code as root and potentially control a server.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/","og_locale":"en_US","og_type":"article","og_title":"cPanel CVE-2026-87899: Root Access Risk and Fixes","og_description":"cPanel patched CVE-2026-87899, allowing a hosting account to execute code as root and potentially control a server.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-24T06:35:41+00:00","article_modified_time":"2026-09-25T04:50:50+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cPanel-CVE-2026-87899.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"cPanel CVE-2026-87899: Root Code Execution and Shared Hosting Risk","datePublished":"2026-09-24T06:35:41+00:00","dateModified":"2026-09-25T04:50:50+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/"},"wordCount":1102,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cPanel-CVE-2026-87899.png?format=webp","articleSection":["Cloud and SaaS","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/","name":"cPanel CVE-2026-87899: Root Access Risk and Fixes","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cPanel-CVE-2026-87899.png?format=webp","datePublished":"2026-09-24T06:35:41+00:00","dateModified":"2026-09-25T04:50:50+00:00","description":"cPanel patched CVE-2026-87899, allowing a hosting account to execute code as root and potentially control a server.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cPanel-CVE-2026-87899.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cPanel-CVE-2026-87899.png?format=webp","width":1340,"height":700,"caption":"cPanel CVE-2026-87899"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cpanel-cve-2026-87899-root-server-control\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"cPanel CVE-2026-87899: Root Code Execution and Shared Hosting Risk"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1941"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1941\/revisions"}],"predecessor-version":[{"id":1949,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1941\/revisions\/1949"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1961"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}