WebPros security advisory (AV26-961)

MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Medium
Used in attacks
Not on CISA’s list
Reported by
1 outlet

As of September 23, 2026, WebPros is affected by vulnerabilities in the following products:

  • Plesk
    • Versions 18.0.34 to 18.0.80.7
    • Version 18.0.81.0
  • Plesk extension "Plesk RESTful API"
    • Versions 2.4.2 to 2.4.6
  • Plesk extension "Site Import"
    • Prior to or equal to 1.12.1
  • WP Toolkit for cPanel
    • Prior to or equal to 6.11.2-10794
  • cPanel/WHM
    • Prior to 11.134.0.57
    • Prior to 11.136.0.41
    • Prior to 11.138.0.8

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-68492Not scored yet

    Product not named yet

    An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.

    Full record →
  • CVE-2026-87898Not scored yet

    Product not named yet

    OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

    Full record →
  • CVE-2026-87900Not scored yet

    Product not named yet

    Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

    Full record →
  • CVE-2026-87899Not scored yet

    Product not named yet

    Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

    Full record →

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber Security ↗Official SourceFirst reported

    2026-09-24 14:43 UTC

Related stories