Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent: cPanel and WHM Security Updates Released

Urgent: cPanel and WHM Security Updates Released

Posted on May 9, 2026 By CWS

Security vulnerabilities in cPanel and Web Host Manager (WHM) have prompted the release of crucial updates. These updates address three significant vulnerabilities that pose risks such as privilege escalation, unauthorized code execution, and denial-of-service (DoS) attacks. Users are strongly advised to apply these patches immediately to safeguard their systems.

Details of the Vulnerabilities

The vulnerabilities identified in cPanel and WHM include three distinct issues. The first, labeled CVE-2026-29201, has a CVSS score of 4.3 and involves insufficient input validation of the feature file name during the “feature::LOADFEATUREFILE” adminbin call, potentially leading to arbitrary file reading.

The second vulnerability, CVE-2026-29202, with a CVSS score of 8.8, is due to inadequate input validation of the “plugin” parameter in the “create_user API” call. This flaw can enable the execution of arbitrary Perl code through the system user of an authenticated account.

The third issue, CVE-2026-29203, also rated at 8.8, concerns unsafe symlink handling, which allows modification of file access permissions using chmod, resulting in DoS or potential privilege escalation.

Patches and Versions

cPanel has issued patches for these vulnerabilities in several versions of cPanel and WHM. The updated versions include 11.136.0.9 and above, covering various prior releases up to 11.86.0.43. Additionally, a direct update, version 110.0.114, is available for users on CentOS 6 or CloudLinux 6.

Users are strongly encouraged to upgrade to the latest versions to ensure optimal security. The updates aim to fortify systems against exploitation and enhance overall protection.

Implications and Recommendations

Although there have been no confirmed cases of these vulnerabilities being exploited in real-world scenarios, the urgency of these updates is underscored by recent threats. Just days before this disclosure, another critical vulnerability (CVE-2026-41940) was leveraged by attackers to deploy Mirai botnet variants and a ransomware strain named Sorry.

Given the potential risks, immediate updates are recommended to prevent potential exploitation. Regularly updating software and applying security patches is crucial to maintaining system integrity and protecting against emerging threats.

In conclusion, staying informed and proactive in applying updates is vital for security in the ever-evolving cyber landscape. Users should prioritize these updates to mitigate vulnerabilities effectively.

The Hacker News Tags:code execution, cPanel, Cybersecurity, Patches, privilege escalation, security updates, software updates, Vulnerabilities, web hosting, WHM

Post navigation

Previous Post: TCLBANKER Trojan Expands Through WhatsApp and Outlook
Next Post: Critical Ollama Security Flaw Exposes Memory Leak Risk

Related Posts

Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit The Hacker News
GlassWorm Malware Disrupted in Major Supply Chain Attack GlassWorm Malware Disrupted in Major Supply Chain Attack The Hacker News
Open Source Web Application Firewall with Zero-Day Detection and Bot Protection Open Source Web Application Firewall with Zero-Day Detection and Bot Protection The Hacker News
What AI Reveals About Web Applications— and Why It Matters What AI Reveals About Web Applications— and Why It Matters The Hacker News
APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains The Hacker News
GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform
  • AI Search Poisoning and Security Risks: Key Cyber News
  • Hackers Target Critical VPN Flaws in Check Point Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform
  • AI Search Poisoning and Security Risks: Key Cyber News
  • Hackers Target Critical VPN Flaws in Check Point Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark