WebPros security advisory (AV26-961)
At a glance
- Severity
- Medium
- Used in attacks
- Not on CISA’s list
- Reported by
- 1 outlet
As of September 23, 2026, WebPros is affected by vulnerabilities in the following products:
- Plesk
- Versions 18.0.34 to 18.0.80.7
- Version 18.0.81.0
- Plesk extension "Plesk RESTful API"
- Versions 2.4.2 to 2.4.6
- Plesk extension "Site Import"
- Prior to or equal to 1.12.1
- WP Toolkit for cPanel
- Prior to or equal to 6.11.2-10794
- cPanel/WHM
- Prior to 11.134.0.57
- Prior to 11.136.0.41
- Prior to 11.138.0.8
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Vulnerability CVE-2026-68492: Arbitrary code execution as root in Plesk via the Plesk RESTful API extension
- Vulnerability CVE-2026-87898: Arbitrary code execution as root in Plesk's Site Import extension
- Security: CVE-2026-87899 Vulnerability in cPanel's CalDAV/CardDAV - September 22, 2026 – cPanel
- Security: CVE-2026-87900 Vulnerability in WP Toolkit Database Creation - September 22, 2026 – cPanel
Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-68492Not scored yet
Product not named yet
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
Full record → - CVE-2026-87898Not scored yet
Product not named yet
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
Full record → - CVE-2026-87900Not scored yet
Product not named yet
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Full record → - CVE-2026-87899Not scored yet
Product not named yet
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Full record →
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-24 14:43 UTC
Related stories
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- [Control systems] Hitachi security advisory (AV26-975)
Canadian Centre for Cyber Security · 2026-09-29
- TeamViewer security advisory (AV26-977)
Canadian Centre for Cyber Security · 2026-09-29
- Mozilla security advisory (AV26-976)
Canadian Centre for Cyber Security · 2026-09-29