Root-Level cPanel/WHM Flaw Puts Every Hosted Account on a Server at Risk
cPanel has patched a critical flaw (CVE-2026-93698) in the Multilang adminbin component that allows arbitrary command execution as root, alongside two stored XSS bugs in WHM's SSL Hosts...
cPanel Security Update Closes Root Escalation and Cross-Tenant Data Access Flaws
cPanel has fixed three flaws that break tenant isolation, including a root-level privilege escalation and cross-account access to calendars, contacts, and WordPress databases. Hosting providers need both current...
Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution
A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...
Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control
CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...
CVE-2026-54420: LiteSpeed cPanel Plugin Zero-Day Actively Exploited to Escalate Privileges to Root
A critical actively exploited zero-day in the LiteSpeed cPanel user-end plugin (CVE-2026-54420) enables attackers to escalate privileges to root, breaking tenant isolation in shared hosting environments. Patch to...
LiteSpeed cPanel Plugin Zero-Day (CVE-2026-48172) Actively Exploited to Gain Server Root Access
LiteSpeed has disclosed and patched a critical zero-day privilege escalation flaw (CVE-2026-48172) in its cPanel user-end plugin that is already being actively exploited in the wild to gain...
Three Critical cPanel and WHM Vulnerabilities Enable Code Execution, File Reads, and DoS Attacks
cPanel has disclosed three critical security vulnerabilities — CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 — affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared platform....
APT Campaign Exploits cPanel CVE-2026-41940 to Breach Government and Military Servers Across South-East Asia
A sophisticated threat actor has exploited the critical cPanel authentication bypass CVE-2026-41940 to compromise government and military servers across South-East Asia, while also deploying a custom zero-day SQL-to-OS...