Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent: cPanel and WHM Security Updates Released

Urgent: cPanel and WHM Security Updates Released

Posted on May 9, 2026 By CWS

Security vulnerabilities in cPanel and Web Host Manager (WHM) have prompted the release of crucial updates. These updates address three significant vulnerabilities that pose risks such as privilege escalation, unauthorized code execution, and denial-of-service (DoS) attacks. Users are strongly advised to apply these patches immediately to safeguard their systems.

Details of the Vulnerabilities

The vulnerabilities identified in cPanel and WHM include three distinct issues. The first, labeled CVE-2026-29201, has a CVSS score of 4.3 and involves insufficient input validation of the feature file name during the “feature::LOADFEATUREFILE” adminbin call, potentially leading to arbitrary file reading.

The second vulnerability, CVE-2026-29202, with a CVSS score of 8.8, is due to inadequate input validation of the “plugin” parameter in the “create_user API” call. This flaw can enable the execution of arbitrary Perl code through the system user of an authenticated account.

The third issue, CVE-2026-29203, also rated at 8.8, concerns unsafe symlink handling, which allows modification of file access permissions using chmod, resulting in DoS or potential privilege escalation.

Patches and Versions

cPanel has issued patches for these vulnerabilities in several versions of cPanel and WHM. The updated versions include 11.136.0.9 and above, covering various prior releases up to 11.86.0.43. Additionally, a direct update, version 110.0.114, is available for users on CentOS 6 or CloudLinux 6.

Users are strongly encouraged to upgrade to the latest versions to ensure optimal security. The updates aim to fortify systems against exploitation and enhance overall protection.

Implications and Recommendations

Although there have been no confirmed cases of these vulnerabilities being exploited in real-world scenarios, the urgency of these updates is underscored by recent threats. Just days before this disclosure, another critical vulnerability (CVE-2026-41940) was leveraged by attackers to deploy Mirai botnet variants and a ransomware strain named Sorry.

Given the potential risks, immediate updates are recommended to prevent potential exploitation. Regularly updating software and applying security patches is crucial to maintaining system integrity and protecting against emerging threats.

In conclusion, staying informed and proactive in applying updates is vital for security in the ever-evolving cyber landscape. Users should prioritize these updates to mitigate vulnerabilities effectively.

The Hacker News Tags:code execution, cPanel, Cybersecurity, Patches, privilege escalation, security updates, software updates, Vulnerabilities, web hosting, WHM

Post navigation

Previous Post: TCLBANKER Trojan Expands Through WhatsApp and Outlook
Next Post: Critical Ollama Security Flaw Exposes Memory Leak Risk

Related Posts

Drift Faces 5M Loss in Social Engineering Heist Drift Faces $285M Loss in Social Engineering Heist The Hacker News
Cybercrime Groups Exploit Vishing for SaaS Attacks Cybercrime Groups Exploit Vishing for SaaS Attacks The Hacker News
Synthetic Identity Fraud Threatens Machine Security Synthetic Identity Fraud Threatens Machine Security The Hacker News
Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data The Hacker News
Citrix Urges Immediate Patching of Critical NetScaler Flaws Citrix Urges Immediate Patching of Critical NetScaler Flaws The Hacker News
Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark