Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical cPanel Vulnerability Allows Root Access

Critical cPanel Vulnerability Allows Root Access

Posted on September 9, 2026 By CWS

cPanel, a widely used web hosting control panel software, recently addressed a critical security vulnerability that posed a significant risk to server security. This flaw, identified as CVE-2026-67401, allowed a hosting account with email-related privileges to execute code with root access, potentially compromising entire servers.

Understanding the Vulnerability

The vulnerability, present in every supported version of cPanel and WHM, was disclosed in an advisory on September 8. Characterized as an SQL injection issue within the EmailTrack module, it enabled authenticated users to create arbitrary files on the server. The flaw did not specify which cPanel feature or privilege was necessary to exploit it, raising concerns among hosting providers and users.

cPanel’s EmailTrack module is designed to monitor email statistics, but the advisory did not confirm if this specific code was affected. The potential for exploitation was significant, as attackers could leverage the vulnerability to gain unauthorized root access, allowing them to manipulate files, databases, and potentially install malware.

Patch Implementation and Server Updates

cPanel has released patched versions across several release lines to mitigate the vulnerability. Administrators are advised to upgrade to the latest builds: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and WP Squared 11.138.1.9. Updates can be performed through WHM’s interface or via command line using cPanel’s specified instructions.

The advisory, however, did not detail interim measures for servers unable to update immediately. In similar past advisories, cPanel provided temporary solutions, such as disabling specific features, which were not mentioned in this instance.

Implications and Future Outlook

While no public exploit code or reports of exploitation have been found as of September 9, the absence of a severity score in the advisory limits the immediate assessment of risk. Previous vulnerabilities have been exploited in ransomware campaigns, highlighting the importance of swift action.

Security experts recommend regular updates and monitoring of server activities to prevent potential exploits. The recent vulnerabilities underscore the need for robust security practices in hosting environments, ensuring that administrative access is tightly controlled and systems are promptly patched against known threats.

cPanel continues to credit security researchers, including Ali Mustafa, for identifying these vulnerabilities, emphasizing the collaborative effort required to maintain a secure digital infrastructure.

The Hacker News Tags:cPanel, CVE, CVE-2026-67401, Cybersecurity, EmailTrack, HackerOne, Hosting, Patch, root access, server security, SQL injection, Vulnerability, web security, WHM

Post navigation

Previous Post: Chrome Users Urged to Update Amid V8 Security Flaw
Next Post: Ivanti Releases Vital Security Updates for Key Products

Related Posts

Critical Security Flaws in Hikvision and Rockwell Products Critical Security Flaws in Hikvision and Rockwell Products The Hacker News
AI Automation Exploits, Telecom Espionage, Prompt Poaching & More AI Automation Exploits, Telecom Espionage, Prompt Poaching & More The Hacker News
Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs The Hacker News
Silver Fox Intensifies Asia Cyber Campaign with New Trojan Silver Fox Intensifies Asia Cyber Campaign with New Trojan The Hacker News
Microsoft Copilot Vulnerabilities Risk Data Exposure Microsoft Copilot Vulnerabilities Risk Data Exposure The Hacker News
Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark