CVE-2026-87900
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
- Published Sep 23, 2026
- CVSS 9.4 critical
- 0.6% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- WebPros security advisory (AV26-961) Canadian Centre for Cyber Security ·
- New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control The Hacker News ·