Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical cPanel/WHM Flaws Risk Server Security

Critical cPanel/WHM Flaws Risk Server Security

Posted on October 2, 2026 By CWS

Recent revelations have uncovered multiple security vulnerabilities within cPanel & WHM, posing significant threats to server integrity. These flaws, announced on September 29, 2026, could enable attackers to execute malicious scripts or run arbitrary commands with root privileges. The vulnerabilities affect all supported versions of cPanel & WHM preceding the latest patch releases.

Immediate Update Required for Administrators

Administrators are urged to update their systems without delay. A successful exploit of the command-execution vulnerability could compromise every hosting account, website, database, and service on the affected server. The most critical of these, identified as CVE-2026-93698, involves the Multilang adminbin component, potentially allowing complete server takeover.

An additional concern is CVE-2026-93029, a stored cross-site scripting flaw located in the WHM Manage SSL Hosts interface. This vulnerability permits unprivileged users to input harmful scripts that execute when viewed by a WHM administrator, potentially allowing attackers to manipulate server settings and manage accounts.

Details on Other Vulnerabilities

Another stored XSS vulnerability, CVE-2026-93697, affects the WHM Mass Modify Accounts interface. Like the SSL Hosts issue, this flaw requires malicious content to be stored and later accessed by an administrator, enabling code execution within their session and unauthorized administrative actions.

The CVE-2026-93698 vulnerability is particularly severe due to inadequate validation in the Multilang adminbin component, leading to potential root-level command execution. This poses a substantial risk in shared-hosting and managed-server environments, as attackers could read or alter data, install malware, or disable security measures.

Patching and Security Recommendations

Currently, no public exploit code has been identified, but the detailed vulnerability advisories might attract malicious actors, especially if WHM interfaces are exposed online. Administrators must update cPanel & WHM to versions 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11, or WP2 11.138.1.13, or newer.

Organizations should also scrutinize WHM administrator activities, account modifications, authentication logs, and any unexpected changes to server or account settings. Implementing firewall rules, VPN access, IP allowlists, and multi-factor authentication can further secure WHM access. Hosting providers are encouraged to assess lower-level account privileges and investigate suspicious inputs related to SSL-host management and account modifications.

The urgency to patch these vulnerabilities cannot be overstated, as failure to do so could expose critical systems and sensitive data to significant risk.

Cyber Security News Tags:command execution, cPanel, cross-site scripting, CVE-2026-93029, CVE-2026-93698, root access, security vulnerabilities, server security, software update, WHM

Post navigation

Previous Post: Red Hat Satellite Flaw: Risk of Root Password Theft
Next Post: Critical GitLab AI Gateway Vulnerability Patched

Related Posts

Critical Updates for SolarWinds Serv-U Fix Major Security Flaws Critical Updates for SolarWinds Serv-U Fix Major Security Flaws Cyber Security News
OpenAI Boosts AI Security by Acquiring Promptfoo OpenAI Boosts AI Security by Acquiring Promptfoo Cyber Security News
Palo Alto Networks to Acquire CyberArk in  Billion Deal Palo Alto Networks to Acquire CyberArk in $25 Billion Deal Cyber Security News
Critical cPanel Security Flaws Threaten User Data Critical cPanel Security Flaws Threaten User Data Cyber Security News
New Zip Slip Vulnerability Allows Attackers to Manipulate ZIP Files During Decompression New Zip Slip Vulnerability Allows Attackers to Manipulate ZIP Files During Decompression Cyber Security News
Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security
  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security
  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark