cPanel disclosed three security flaws, including a critical vulnerability in its CalDAV/CardDAV service that allows any hosting account holder to execute code as root and gain full server control. A second flaw in the WP Toolkit plugin enables users to modify databases belonging to other accounts, while a third permits reading other accounts' calendar data. cPanel has released patched versions for all three issues.