Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to RCE Attacks

Posted on November 14, 2025November 14, 2025 By CWS

A extreme distant code execution (RCE) vulnerability has been found in Imunify360 AV, a broadly used malware scanner defending roughly 56 million web sites.

The safety flaw, just lately patched by CloudLinux, permits attackers to execute arbitrary instructions and probably take full management of internet hosting servers.

Patchstack researchers found a flaw in Imunify360 AV’s deobfuscation logic used to investigate malicious PHP code.

Imunify360 AV RCE Vulnerability

Attackers can create specifically encoded PHP information that mislead the scanner into executing dangerous features, comparable to system(), exec(), or eval(), throughout evaluation.

As a result of the scanner sometimes runs with root privileges, profitable exploitation may end up in an entire server takeover.

The Patchstack evaluation highlights a regarding flaw: deobfuscation is robotically enabled within the default configuration of Imunify360 AV for all scan varieties.

AttributeDetailsVulnerability TypeRemote Code Execution (RCE)Product AffectedImunify360 AV (AI-Bolit)Affected VersionsPrior to v32.7.4.0Patched Versionv32.7.4.0 and later

Together with background scans, on-demand scans, and fast account scans. This implies susceptible programs are constantly in danger at any time when the scanner operates. On shared internet hosting environments, this vulnerability poses distinctive hazard.

Attackers who compromise a single web site can escalate privileges to realize root entry, compromising each web site and buyer on the identical server.

This lateral motion functionality makes the vulnerability particularly extreme for internet hosting suppliers serving a number of shoppers. CloudLinux launched a patch on October 21, 2025, however has notably not issued a proper CVE task or safety advisory.

Details about the vulnerability appeared on their Zendesk help web page on November 4, 2025, despite the fact that exploitation particulars had been circulating since late October.

Patchstack consultants suggest internet hosting firms not solely patch instantly but in addition examine whether or not their servers have already been compromised.

Internet hosting firms ought to improve to Imunify360 AV model 32.7.4.0 or later directly and conduct forensic checks for indicators of exploitation on their infrastructure.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Attacks, Critical, Exposes, Imunify360, Linuxhosted, Million, RCE, Vulnerability, Websites

Post navigation

Previous Post: Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover
Next Post: Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

Related Posts

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges Cyber Security News
Angular Platform Vulnerability Allows Malicious Code Execution Via Weaponized SVG Animation Files Cyber Security News
Windows Ancillary for WinSock 0-Day Vulnerability Let Attackers Escalate Privileges Cyber Security News
Hackers Weaponize QR Codes Embedded with Malicious Links to Steal Sensitive Information Cyber Security News
Threats Actors Poisoned Bing Search Results to Deliver Bumblebee Malware if User Searched for ‘ManageEngine OpManager’ Cyber Security News
New Phishing Attack Impersonates as DWP Attacking Users to Steal Credit Card Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
  • Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000
  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
  • Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000
  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark