CVE-2026-67402: Critical RCE in ConfigServer Firewall — Update CSF to 16.31 Now

If your server runs cPanel with ConfigServer Firewall (CSF), drop what you’re doing and check your CSF version. On September 3, 2026, cPanel pushed a critical patch for CVE-2026-67402 — a remote code execution vulnerability in CSF’s Messenger service that lets an unauthenticated attacker run arbitrary commands as the Apache user. That’s a bad sentence to read about a piece of software whose entire job is to protect your server. What Is CSF, and Why Did cPanel Inherit It? ConfigServer Security & Firewall has been a staple of cPanel/WHM setups for years — it’s the iptables-based firewall layer that handles port blocking, login failure detection, and email alerts. The original developer discontinued it on August 31, 2025 and released the code as open-source under GPLv3. cPanel (now WebPros) stepped in on February 25, 2026 and forked it, taking over security maintenance. ...

September 13, 2026 · 3 min

CVE-2026-65643: Any cPanel User with Parked Domains Can Get Root — Patch Now

On August 27, 2026, cPanel pushed an unscheduled security update and sent a customer notification that most people probably skimmed past. They shouldn’t have. The flaw, assigned CVE-2026-65643, lets any authenticated cPanel account that has permission to add parked or addon domains create arbitrary files on the underlying server — which in practice means full root-level code execution. That’s not a privilege escalation hidden behind multiple hoops. That’s a regular shared hosting customer owning the machine. ...

September 3, 2026 · 4 min

CVE-2026-41940: The cPanel Zero-Day That Sat Unpatched for Two Months

On April 28, 2026, cPanel released an emergency patch for CVE-2026-41940 — a CVSS 9.8 authentication bypass that, as it turned out, attackers had been quietly exploiting since approximately February 23. That is roughly two months of zero-day exposure across an estimated 1.5 million internet-facing cPanel & WHM instances. CISA promptly added it to its Known Exploited Vulnerabilities catalog, which is the agency’s way of saying: stop reading and go patch. ...

May 4, 2026 · 4 min