logo

New cPanel and WHM Flaws Enable Code Execution, DoS Attacks

ID: 253de550-3758-5a98-822b-dfe96749c39c

STIX ID: report--253de550-3758-5a98-822b-dfe96749c39c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-10

Date Updated: 2026-05-11

Author: Guru Baran

...
...

**Executive Summary:** cPanel disclosed three critical vulnerabilities affecting cPanel & WHM and WP Squared that permit arbitrary file reads (path traversal), Perl code injection enabling RCE, and unsafe symlink/chmod handling that can cause DoS and privilege escalation; patches were released on May 8, 2026, and administrators are urged to apply updates immediately (/scripts/upcp --force) and verify installed versions to mitigate widespread risk to shared hosting environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.