
If you run self-hosted https://Cal.com, stop what you're doing and check your version. CVE-2026-57858 is a stored XSS vuln in the booking page analytics config. Here's what to audit Thursday:
Post summary
A stored XSS vulnerability (CVE‑2026‑57858) in self‑hosted Cal.com’s booking analytics config is disclosed, urging users to audit their installations.

