<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Firewall on kalfaoglu.net</title><link>https://blog.kalfaoglu.net/tags/firewall/</link><description>Recent content in Firewall on kalfaoglu.net</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 13 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.kalfaoglu.net/tags/firewall/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-67402: Critical RCE in ConfigServer Firewall — Update CSF to 16.31 Now</title><link>https://blog.kalfaoglu.net/posts/2026-09-13-csf-cve-2026-67402-en/</link><pubDate>Sun, 13 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.kalfaoglu.net/posts/2026-09-13-csf-cve-2026-67402-en/</guid><description>&lt;p&gt;If your server runs cPanel with ConfigServer Firewall (CSF), drop what you&amp;rsquo;re doing and check your CSF version. On September 3, 2026, cPanel pushed a critical patch for &lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-67402"&gt;CVE-2026-67402&lt;/a&gt; — a remote code execution vulnerability in CSF&amp;rsquo;s Messenger service that lets an unauthenticated attacker run arbitrary commands as the Apache user. That&amp;rsquo;s a bad sentence to read about a piece of software whose entire job is to protect your server.&lt;/p&gt;
&lt;h2 id="what-is-csf-and-why-did-cpanel-inherit-it"&gt;What Is CSF, and Why Did cPanel Inherit It?&lt;/h2&gt;
&lt;p&gt;ConfigServer Security &amp;amp; Firewall has been a staple of cPanel/WHM setups for years — it&amp;rsquo;s the iptables-based firewall layer that handles port blocking, login failure detection, and email alerts. The original developer discontinued it on August 31, 2025 and released the code as open-source under GPLv3. cPanel (now WebPros) stepped in on February 25, 2026 and forked it, taking over security maintenance.&lt;/p&gt;</description></item></channel></rss>