Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent: cPanel and WHM Security Updates Released

Urgent: cPanel and WHM Security Updates Released

Posted on May 9, 2026 By CWS

Security vulnerabilities in cPanel and Web Host Manager (WHM) have prompted the release of crucial updates. These updates address three significant vulnerabilities that pose risks such as privilege escalation, unauthorized code execution, and denial-of-service (DoS) attacks. Users are strongly advised to apply these patches immediately to safeguard their systems.

Details of the Vulnerabilities

The vulnerabilities identified in cPanel and WHM include three distinct issues. The first, labeled CVE-2026-29201, has a CVSS score of 4.3 and involves insufficient input validation of the feature file name during the “feature::LOADFEATUREFILE” adminbin call, potentially leading to arbitrary file reading.

The second vulnerability, CVE-2026-29202, with a CVSS score of 8.8, is due to inadequate input validation of the “plugin” parameter in the “create_user API” call. This flaw can enable the execution of arbitrary Perl code through the system user of an authenticated account.

The third issue, CVE-2026-29203, also rated at 8.8, concerns unsafe symlink handling, which allows modification of file access permissions using chmod, resulting in DoS or potential privilege escalation.

Patches and Versions

cPanel has issued patches for these vulnerabilities in several versions of cPanel and WHM. The updated versions include 11.136.0.9 and above, covering various prior releases up to 11.86.0.43. Additionally, a direct update, version 110.0.114, is available for users on CentOS 6 or CloudLinux 6.

Users are strongly encouraged to upgrade to the latest versions to ensure optimal security. The updates aim to fortify systems against exploitation and enhance overall protection.

Implications and Recommendations

Although there have been no confirmed cases of these vulnerabilities being exploited in real-world scenarios, the urgency of these updates is underscored by recent threats. Just days before this disclosure, another critical vulnerability (CVE-2026-41940) was leveraged by attackers to deploy Mirai botnet variants and a ransomware strain named Sorry.

Given the potential risks, immediate updates are recommended to prevent potential exploitation. Regularly updating software and applying security patches is crucial to maintaining system integrity and protecting against emerging threats.

In conclusion, staying informed and proactive in applying updates is vital for security in the ever-evolving cyber landscape. Users should prioritize these updates to mitigate vulnerabilities effectively.

The Hacker News Tags:code execution, cPanel, Cybersecurity, Patches, privilege escalation, security updates, software updates, Vulnerabilities, web hosting, WHM

Post navigation

Previous Post: TCLBANKER Trojan Expands Through WhatsApp and Outlook
Next Post: Critical Ollama Security Flaw Exposes Memory Leak Risk

Related Posts

GreatXML Exploit Circumvents Windows BitLocker Security GreatXML Exploit Circumvents Windows BitLocker Security The Hacker News
GitHub Probes Alleged Security Breach by TeamPCP GitHub Probes Alleged Security Breach by TeamPCP The Hacker News
Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers The Hacker News
TeamPCP Exploits LiteLLM via CI/CD Flaw TeamPCP Exploits LiteLLM via CI/CD Flaw The Hacker News
China-Linked TA4922 Broadens Cyber Attacks Globally China-Linked TA4922 Broadens Cyber Attacks Globally The Hacker News
North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Unified CM Flaw Exploited by Hackers
  • Anthropic AI Exposes Security Gaps in U.S. Systems
  • Anthropic Outage Disrupts Claude Models
  • In-Browser Data Inspection Revolutionizes Phishing Analysis
  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Unified CM Flaw Exploited by Hackers
  • Anthropic AI Exposes Security Gaps in U.S. Systems
  • Anthropic Outage Disrupts Claude Models
  • In-Browser Data Inspection Revolutionizes Phishing Analysis
  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark