Recent revelations have uncovered multiple security vulnerabilities within cPanel & WHM, posing significant threats to server integrity. These flaws, announced on September 29, 2026, could enable attackers to execute malicious scripts or run arbitrary commands with root privileges. The vulnerabilities affect all supported versions of cPanel & WHM preceding the latest patch releases.
Immediate Update Required for Administrators
Administrators are urged to update their systems without delay. A successful exploit of the command-execution vulnerability could compromise every hosting account, website, database, and service on the affected server. The most critical of these, identified as CVE-2026-93698, involves the Multilang adminbin component, potentially allowing complete server takeover.
An additional concern is CVE-2026-93029, a stored cross-site scripting flaw located in the WHM Manage SSL Hosts interface. This vulnerability permits unprivileged users to input harmful scripts that execute when viewed by a WHM administrator, potentially allowing attackers to manipulate server settings and manage accounts.
Details on Other Vulnerabilities
Another stored XSS vulnerability, CVE-2026-93697, affects the WHM Mass Modify Accounts interface. Like the SSL Hosts issue, this flaw requires malicious content to be stored and later accessed by an administrator, enabling code execution within their session and unauthorized administrative actions.
The CVE-2026-93698 vulnerability is particularly severe due to inadequate validation in the Multilang adminbin component, leading to potential root-level command execution. This poses a substantial risk in shared-hosting and managed-server environments, as attackers could read or alter data, install malware, or disable security measures.
Patching and Security Recommendations
Currently, no public exploit code has been identified, but the detailed vulnerability advisories might attract malicious actors, especially if WHM interfaces are exposed online. Administrators must update cPanel & WHM to versions 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11, or WP2 11.138.1.13, or newer.
Organizations should also scrutinize WHM administrator activities, account modifications, authentication logs, and any unexpected changes to server or account settings. Implementing firewall rules, VPN access, IP allowlists, and multi-factor authentication can further secure WHM access. Hosting providers are encouraged to assess lower-level account privileges and investigate suspicious inputs related to SSL-host management and account modifications.
The urgency to patch these vulnerabilities cannot be overstated, as failure to do so could expose critical systems and sensitive data to significant risk.
