New cPanel and WHM Flaws Enable Code Execution, DoS Attacks
ID: 253de550-3758-5a98-822b-dfe96749c39c
STIX ID: report--253de550-3758-5a98-822b-dfe96749c39c
Feed Name: cybersecurityNews.com
**Executive Summary:** cPanel disclosed three critical vulnerabilities affecting cPanel & WHM and WP Squared that permit arbitrary file reads (path traversal), Perl code injection enabling RCE, and unsafe symlink/chmod handling that can cause DoS and privilege escalation; patches were released on May 8, 2026, and administrators are urged to apply updates immediately (/scripts/upcp --force) and verify installed versions to mitigate widespread risk to shared hosting environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
